Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Chronological Source Flow
Back

AI Fusion Summary

Cato AI Labs discovered two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, in the Cursor AI code editor. Named DuneSlide, these flaws allowed prompt injections to escape the safety sandbox and execute arbitrary commands on developer computers without user approval. Rated up to 9.8, the vulnerabilities affected a tool used by over half of the Fortune 500. Cursor addressed these security risks with patches released in version 3.0 on April 2, prior to the public disclosure.
Community Comments
Loading updates...
0