Two critical vulnerabilities, identified as CVE-2026-50548 and CVE-2026-50549, have been found in the Cursor AI code editor. These vulnerabilities, termed DuneSlide, have a CVSS score of 9.8, indicating their high severity. They allow potentially harmful remote code execution by escaping the constraints of the application's security sandbox.
The vulnerabilities permit command execution outside Cursor's safety sandbox, a protective layer intended to restrict command impact on the system. An attacker could exploit these flaws through prompt injection without any user interaction, enabling unauthorized commands to run at the operating system level.
Cato AI Labs, who discovered these vulnerabilities, underscores the necessity for immediate updates to the latest release, Cursor 3.0, which contains necessary patches. Previous versions are vulnerable, with the tool's wide usage across Fortune 500 companies intensifying the need for swift action.
These vulnerabilities could have broad implications, particularly for large enterprises using Cursor. The flaws compromise system security by enabling remote code execution, necessitating urgent mitigation through updates to safeguard against potential exploits.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Two critical vulnerabilities in the Cursor AI code editor could allow attackers to execute remote code at the OS level. These flaws could lead to significant security risks as they bypass the IDE's security sandbox through command injection and improper file path resolution.
Two critical vulnerabilities in Cursor, tracked as CVE-2026-50548 and CVE-2026-50549, could enable command execution outside the editor's safety sandbox, affecting many Fortune 500 companies. The flaws, identified by Cato AI Labs and rated 9.8/10 in severity, can be exploited through prompt injection without user interaction, necessitating an immediate software update to the patched version 3.0.