Two critical Cursor IDE vulnerabilities (CVE-2026-50548 and CVE-2026-50549), collectively dubbed DuneSlide, allow prompt injection attacks to escape the editor's command sandbox with no user interaction required. Both score 9.8 on CVSS 3.1. The first flaw exploits the run_terminal_cmd tool's working_directory parameter to write outside the sandbox; the second abuses a symlink resolution fallback. An attacker can deliver malicious instructions via MCP server responses or fetched web pages that the AI agent reads during normal operation. Once the sandbox helper is overwritten, subsequent commands run unsandboxed with full developer privileges. Cursor patched both issues in version 3.0 (released April 2). All 2.x builds remain vulnerable. Developers should update immediately and treat all agent-readable content as untrusted input.

5m read timeFrom latesthackingnews.com
Post cover image
Table of contents
How the Cursor IDE vulnerabilities actually workNo click neededWhat the CVSS score actually meansHow Cursor respondedWhat to do about it
121 Impressions