Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Researchers at Cato AI Labs have uncovered two critical vulnerabilities in Cursor, an AI-powered code editor, that could allow attackers to execute arbitrary commands on a developer's machine by crafting a seemingly harmless prompt. These vulnerabilities, known as DuneSlide, have been assigned CVE-2026-50548 and CVE-2026-50549 and carry a severity rating of 9.8 out of 10. This discovery underscores the importance of robust security measures in development tools, as it highlights how even trusted software can be exploited if not properly vetted, potentially leading to significant security breaches.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.