Evidence record / cursor
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-cursor-hooks-beforemcpexecution-gains-server-identity-and-the-doc-tells-allowlist-hooks-to-deny
Hooks: beforeMCPExecution gains server identity, and the doc tells allowlist hooks to deny on missing names. Before, a hook could only tell which MCP server a call targeted by matching a URL or a free-form command string. Now there is a stable server key.
Channel: docs-only. Half: both. Date: between 2026-08-20 and 2026-09-02 (bracketed by captures).
Operator consequence: Re-audit any MCP allowlist hook: if it matches on command, it can be evaded by a server launched with a different path or via ${CURSOR_PLUGIN_ROOT} expansion. Switch to mcp_server_name + tool_name, and fail closed when the field is absent (older client builds). Enterprise-managed hooks now reach self-hosted workers, so a managed hook is a control on those machines too.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-cursor-hooks-beforemcpexecution-gains-server-identity-and-the-doc-tells-allowlist-hooks-to-deny
Profile citations
- cursor / claim / mcp-hook-server-identity
Source links
Primary links, including exact changelog lines when available.
- official docs2026-09-21-cursor-hooks-beforemcpexecution-gains-server-identity-and-the-doc-tells-allowlist-hooks-to-denyweb.archive.org/web/20260820212459/https://cursor.com/docs/hooksofficial docs2026-09-21-cursor-hooks-beforemcpexecution-gains-server-identity-and-the-doc-tells-allowlist-hooks-to-denyweb.archive.org/web/20260902233313/https://cursor.com/docs/hooks
Versioned source: run artifact