Vulnerabilities · 73 days ago

Cursor Sandbox Breaks on Trusted AI Inputs

Cursor’s sandbox does not hold when its AI agent is fed hostile content. Hidden instructions in a page or connected service can steer the agent into changing the helper that enforces containment, so later terminal commands run on the developer’s machine instead of inside the box.

Cato AI Labs found two zero-day flaws, tracked as CVE-2026-50548 and CVE-2026-50549 and named DuneSlide. Both are patched in Cursor 3.0, and every version before 3.0 is affected. The issue hits Cursor’s AI agent path, including web search, MCP integrations, and other external content sources.

The practical failure is simple: patching the bug does not make the content trustworthy. If the assistant can read outside input and act on it, that input can become code execution through the assistant’s own trust path.

CVE-2026-50548

NVD KEV

CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61st percentile).

CVE-2026-50549

NVD KEV

CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61st percentile).

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-04

Editions

Related stories