Loading video...
Video Failed to Load
Also, Cursor can also connect to Caido’s proxy on localhost via its embedded browser when a proxy is needed, just saying 👀. Here it used the proxy to solve a traversal sequence that had been stripped by a superfluous URL-decode from PortSwigger Labs. #BugBounty #bugbountytip
16,613 views • 11 months ago •via X (Twitter)
5 Comments

btw, I wanted to say this a long time ago @CaidoIO uses an old, vulnerable version of Chromium 130.0.6723.0 . This version has public critical vulnerabilities , some of them with public POCs This means any script kiddies can hack you if you are using Caido by sending you a URL! I hope the team of @CaidoIO starts doing the patch management ASAP

@CaidoIO As @sw33tLie said, since this was part of @PortSwigger labs the model was most likely already trained to find these, but that doesn't change the fact I discovered multiple real-world flaws using those tools/methods on bug-bounty targets 🤷♂️ Reference:

@cursor_ai @CaidoIO You also can download "Ebka AI" from the store and connect Caido as an MCP to Cursor

@cursor_ai @CaidoIO Wild stuff. Can confirm 🫡😛

@cursor_ai @CaidoIO
