Cursor patches DuneSlide flaws CVE-2026-50548 and CVE-2026-50549 that could let malicious prompts run code on developers’ computers

Cursor fixed two critical security flaws that could let a booby-trapped prompt or attacker-controlled payload escape the AI coding editor’s sandbox and run code on the underlying computer. Cato Networks says CVE-2026-50548 and CVE-2026-50549, both rated 9.8, affected Cursor before version 3.0 and enabled zero-click prompt-injection attacks by abusing automatic terminal command execution, working-directory allowlisting, and symlink-based path resolution to overwrite the cursorsandbox executable and achieve operating-system-level remote code execution.
Why it matters: Developers using vulnerable Cursor versions could have their machines compromised just by getting the IDE to ingest malicious content, making this a high-impact workstation risk. Organizations should update Cursor to version 3.0 or later and treat untrusted prompts, repositories, and MCP-connected content as potentially hostile.

Sources

Critical Cursor AI IDE Flaws Could Lead to OS-Level Remote Code Execution
Ionut Arghire 2026.07.03 100% relevant
This article establishes a distinct tracked story by naming the concrete event: the DuneSlide disclosure and patch for Cursor flaws CVE-2026-50548 and CVE-2026-50549 enabling sandbox escape and OS-level remote code execution.
← Back to all stories