DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE
ID: f834d913-7463-588b-909f-0cf07a486a97
STIX ID: report--f834d913-7463-588b-909f-0cf07a486a97
Feed Name: Cato Networks
Threat Score
Cato AI Labs disclosed two critical zero-click RCE vulnerabilities (DuneSlide) in Cursor IDE that allow prompt-injected LLM outputs to manipulate the sandbox working_directory and exploit symlink canonicalization failures to overwrite critical binaries (e.g., cursorsandbox), resulting in sandbox escape and full system compromise; Cursor addressed the issues in version 3.0 and the issues were assigned CVE-2026-50548 and CVE-2026-50549.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
