Two bugs in Cursor, an AI code editor, can allow a simple, seemingly innocent prompt to escape the processor’s protective sandbox and execute any command on a developer’s computer. Cato AI Labs discovered the two bugs and named them DuneSlide. They are listed as CVE-2026-50548 and CVE-2026-50549, and are rated 9.8 out of 10 (or 9.3 according to the newer CVSS 4.0 scale).
See also: Escape Exploit for Chrome Sandbox sells for $1 million

The fix is already available. Both bugs were fixed in Cursor 3.0, which was released on April 2, and any version before 3.0 is affected. Cursor's maker says that more than half of Fortune 500 companies use the tool, so if you're using it, update now.
Starting from the 2.x line, Cursor executes terminal commands issued by its AI agent inside a sandbox by default: a locked box that restricts what those commands can touch, so that an accidental command cannot destroy the machine.
DuneSlide is about getting out of that box. The way it gets in is through prompt injection. The attacker never types at your cursor. They plant commands inside something your agent reads on your behalf, like a connected service via the Model Context Protocol (MCP) or a page returned from a web search. You ask a normal question, the hidden commands come along, and because no click or approval is required from you, the attack is “zero-click.”
Both bugs use the same trick: get the agent to write to a file it shouldn't be allowed to write to, and then use that writing to disable the sandbox.
CVE-2026-50548 exploits a setting. The sandbox allows writes to the working directory of a command, and this directory is an optional parameter, working_directory, to Cursor's run_terminal_cmd tool . When the agent sets it to a non-default path, Cursor adds that path to the allowed write list without prompting. Injectable commands direct it to a system file instead of the project.
See also: Cursor autorun allows arbitrary code execution

Replace the sandbox utility itself (on macOS, /Applications/Cursor.app/Contents/Resources/app/resources/helpers/cursorsandbox), and subsequent commands are executed without any sandboxing. Startup files like ~/.zshrc also work as targets.
CVE-2026-50549 exploits a security check. Before writing, Cursor resolves shortcuts (symlinks) to verify that the actual target is within your project. The bug is the alternative: when this check fails, either because the target does not exist or the attacker removes read access from a folder in the path, Cursor gives up and trusts the in-project path of the shortcut.
An attacker creates a shortcut that points outside the project, causes the check to fail, and Cursor writes directly through it to the same sandbox utility. Same escape, different door. Once the sandbox is neutralized, the next command is executed as you. This means control of the developer's machine, as well as any cloud or SaaS workspaces the processor is connected to. It all starts with an innocent prompt.
There is no evidence that this has been used in actual attacks. Cato presents this as research, not an active campaign, and the public vulnerability file shows no known exploits at the time of publication. Cato reported both issues on February 19. Cursor dismissed them four days later, saying that its threat model does not cover misuse of MCP servers, even standard ones like the official Linear workspace.
Cato escalated the issue on February 26. Cursor resubmitted the reports, evaluated them, and released both fixes in version 3.0. CVE IDs were assigned on June 5. Cursor published its own advisory on the symlink bug, and its NVD file is active.
DuneSlide is the latest in a series of Cursor bugs that start with a poisoned prompt and end in code execution, each of which defeats a different protection. Hacker News covered the previous rounds:
See also: Terrarium Sandbox: Critical vulnerability allows root code execution
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CurXecute (CVE-2025-54135, August 2025) came from the same team, then operating as Aim Security. A reposted Slack message overwrote ~/.cursor/mcp.json and executed commands even after the user canceled the edit. Fixed in version 1.3.
