CVE-2026-50548
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61st percentile).
Vulnerabilities · 73 days ago
Cursor’s sandbox does not hold when its AI agent is fed hostile content. Hidden instructions in a page or connected service can steer the agent into changing the helper that enforces containment, so later terminal commands run on the developer’s machine instead of inside the box.
Cato AI Labs found two zero-day flaws, tracked as CVE-2026-50548 and CVE-2026-50549 and named DuneSlide. Both are patched in Cursor 3.0, and every version before 3.0 is affected. The issue hits Cursor’s AI agent path, including web search, MCP integrations, and other external content sources.
The practical failure is simple: patching the bug does not make the content trustworthy. If the assistant can read outside input and act on it, that input can become code execution through the assistant’s own trust path.
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61st percentile).
CVSS 9.8 CRITICAL: cursor is a code editor built for programming with AI. EPSS 1% (61st percentile).
3 sources covering this story
Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system.
Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
The two vulnerabilities reveal a native flaw in LLMs and AI-assisted IDEs affecting more than just Cursor.
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Patched in Cursor 3.0, CVE-2026-50548 and CVE-2026-50549 could enable zero-click command execution via hidden instructions.
Part of the PlainSec briefing for 2026-07-04