CVE-2026-50548
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61º percentile).
Vulnerabilità · 88 giorni fa
Il punto debole non è l’errore dell’agente, ma il presupposto che il sandbox basti a contenerlo. Qui un contenuto esterno già letto dall’assistente può fargli scrivere dove non dovrebbe, fino a spegnere il meccanismo che limita i comandi successivi e trasformare un input non fidato in esecuzione sulla macchina dello sviluppatore.
Cato AI Labs ha segnalato due zero-day, CVE-2026-50548 e CVE-2026-50549, entrambi corretti in Cursor 3.0; tutte le versioni precedenti restano esposte. Le due falle permettono una prompt injection zero-click tramite pagine web o servizi collegati via MCP, e portano il terminale dell’agente a uscire dal sandbox e a correre senza più isolamento.
Per i team che usano Cursor con web search, integrazioni MCP o altre sorgenti esterne, il confine tra leggere e agire non è più affidabile: il contenuto esterno va trattato come ostile perché può alterare il guardrail stesso dell’assistente.
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61º percentile).
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61º percentile).
3 fonti che coprono questa storia
Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system.
Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
The two vulnerabilities reveal a native flaw in LLMs and AI-assisted IDEs affecting more than just Cursor.
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Patched in Cursor 3.0, CVE-2026-50548 and CVE-2026-50549 could enable zero-click command execution via hidden instructions.
Part of the PlainSec briefing for 2026-07-04