HomeSecurityCritical errors in Cursor allow Sandbox escape and command execution

Critical bugs in Cursor allow sandbox escape and command execution

Two bugs in Cursor, an AI code editor, can allow a simple, seemingly innocent prompt to escape the processor’s protective sandbox and execute any command on a developer’s computer. Cato AI Labs discovered the two bugs and named them DuneSlide. They are listed as CVE-2026-50548 and CVE-2026-50549, and are rated 9.8 out of 10 (or 9.3 according to the newer CVSS 4.0 scale).

See also: Escape Exploit for Chrome Sandbox sells for $1 million

Article Image: Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

The fix is ​​already available. Both bugs were fixed in Cursor 3.0, which was released on April 2, and any version before 3.0 is affected. Cursor's maker says that more than half of Fortune 500 companies use the tool, so if you're using it, update now.

Starting from the 2.x line, Cursor executes terminal commands issued by its AI agent inside a sandbox by default: a locked box that restricts what those commands can touch, so that an accidental command cannot destroy the machine.

DuneSlide is about getting out of that box. The way it gets in is through prompt injection. The attacker never types at your cursor. They plant commands inside something your agent reads on your behalf, like a connected service via the Model Context Protocol (MCP) or a page returned from a web search. You ask a normal question, the hidden commands come along, and because no click or approval is required from you, the attack is “zero-click.”

Both bugs use the same trick: get the agent to write to a file it shouldn't be allowed to write to, and then use that writing to disable the sandbox.

CVE-2026-50548 exploits a setting. The sandbox allows writes to the working directory of a command, and this directory is an optional parameter, working_directory, to Cursor's run_terminal_cmd tool . When the agent sets it to a non-default path, Cursor adds that path to the allowed write list without prompting. Injectable commands direct it to a system file instead of the project.

See also: Cursor autorun allows arbitrary code execution

SpaceX and Cursor AI code development partnership worth $60 billion

Replace the sandbox utility itself (on macOS, /Applications/Cursor.app/Contents/Resources/app/resources/helpers/cursorsandbox), and subsequent commands are executed without any sandboxing. Startup files like ~/.zshrc also work as targets.

CVE-2026-50549 exploits a security check. Before writing, Cursor resolves shortcuts (symlinks) to verify that the actual target is within your project. The bug is the alternative: when this check fails, either because the target does not exist or the attacker removes read access from a folder in the path, Cursor gives up and trusts the in-project path of the shortcut.

An attacker creates a shortcut that points outside the project, causes the check to fail, and Cursor writes directly through it to the same sandbox utility. Same escape, different door. Once the sandbox is neutralized, the next command is executed as you. This means control of the developer's machine, as well as any cloud or SaaS workspaces the processor is connected to. It all starts with an innocent prompt.

There is no evidence that this has been used in actual attacks. Cato presents this as research, not an active campaign, and the public vulnerability file shows no known exploits at the time of publication. Cato reported both issues on February 19. Cursor dismissed them four days later, saying that its threat model does not cover misuse of MCP servers, even standard ones like the official Linear workspace.

Cato escalated the issue on February 26. Cursor resubmitted the reports, evaluated them, and released both fixes in version 3.0. CVE IDs were assigned on June 5. Cursor published its own advisory on the symlink bug, and its NVD file is active.

DuneSlide is the latest in a series of Cursor bugs that start with a poisoned prompt and end in code execution, each of which defeats a different protection. Hacker News covered the previous rounds:

See also: Terrarium Sandbox: Critical vulnerability allows root code execution

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Critical bugs in Cursor allow sandbox escape and command execution

CurXecute (CVE-2025-54135, August 2025) came from the same team, then operating as Aim Security. A reposted Slack message overwrote ~/.cursor/mcp.json and executed commands even after the user canceled the edit. Fixed in version 1.3.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS