<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Critical RCE Flaws in Cursor IDE Let Attackers Escape Sandbox With Zero Clicks

Critical vulnerabilities in Cursor IDE allowed remote code execution without user interaction. Fixed in Cursor 3.0 — anyone on an older build is exposed.
Content Team

Two critical vulnerabilities in Cursor IDE — the AI coding tool used by over half of Fortune 500 companies — could give attackers full remote code execution without any user interaction. Discovered by Cato AI Labs and dubbed "DuneSlide," both flaws carry a 9.8 CVSS score (CVE-2026-50548 and CVE-2026-50549).

The attack works through prompt injection: a victim simply types a normal prompt that accidentally pulls in attacker-controlled content — from a poisoned web search or rogue MCP server. From there, attackers can overwrite core sandbox binaries and compromise both the local machine and connected SaaS workspaces.

Cursor 3.0, out since April 2, fixes both. Every earlier version is affected, and there's no sign of exploitation in the wild. Getting there took some pushing: Cursor rejected Cato's initial report in February, saying its threat model didn't account for MCP server misuse, and only reopened the cases after the researchers escalated.

Cato says more disclosures are coming across other AI coding agents.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo