logo

Critical Cursor IDE RCE Vulnerabilities Enable Prompt Injection in Zero-Click

ID: 1f8e5ea2-3530-52e2-8212-cd01ec5f8dc1

STIX ID: report--1f8e5ea2-3530-52e2-8212-cd01ec5f8dc1

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-07-01

Date Updated: 2026-07-02

Author: Guru Baran

...
...

Two critical RCE vulnerabilities (DuneSlide — CVE-2026-50548 and CVE-2026-50549) in Cursor IDE allow prompt-injection attacks to escape the Cursor 2.x sandbox and overwrite the cursorsandbox helper or other sensitive files, resulting in unsandboxed remote code execution; both are CVSS 9.8, require no privileges or user interaction, and can be triggered by poisoned inputs (e.g., MCP server responses or search results), potentially impacting many enterprise users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.