Cursor’s sandbox does not hold when its AI agent is fed hostile content. Hidden instructions in a page or connected service can steer the agent into changing the helper that enforces containment, so later terminal commands run on the developer’s machine instead of inside the box.
Cato AI Labs found two zero-day flaws, tracked as CVE-2026-50548 and CVE-2026-50549 and named DuneSlide. Both are patched in Cursor 3.0, and every version before 3.0 is affected. The issue hits Cursor’s AI agent path, including web search, MCP integrations, and other external content sources.
The practical failure is simple: patching the bug does not make the content trustworthy. If the assistant can read outside input and act on it, that input can become code execution through the assistant’s own trust path.