Critical Cursor IDE RCE Vulnerabilities Enable Prompt Injection in Zero-Click
ID: 1f8e5ea2-3530-52e2-8212-cd01ec5f8dc1
STIX ID: report--1f8e5ea2-3530-52e2-8212-cd01ec5f8dc1
Feed Name: cybersecurityNews.com
Threat Score
Two critical RCE vulnerabilities (DuneSlide — CVE-2026-50548 and CVE-2026-50549) in Cursor IDE allow prompt-injection attacks to escape the Cursor 2.x sandbox and overwrite the cursorsandbox helper or other sensitive files, resulting in unsandboxed remote code execution; both are CVSS 9.8, require no privileges or user interaction, and can be triggered by poisoned inputs (e.g., MCP server responses or search results), potentially impacting many enterprise users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
