logo

DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE

ID: f834d913-7463-588b-909f-0cf07a486a97

STIX ID: report--f834d913-7463-588b-909f-0cf07a486a97

Feed Name: Cato Networks

Threat Score
85/100

Date Published: 2026-07-01

Date Updated: 2026-07-23

Author: Tal Biran

ADMIRALTY:B6
...
...

Cato AI Labs disclosed two critical zero-click RCE vulnerabilities (DuneSlide) in Cursor IDE that allow prompt-injected LLM outputs to manipulate the sandbox working_directory and exploit symlink canonicalization failures to overwrite critical binaries (e.g., cursorsandbox), resulting in sandbox escape and full system compromise; Cursor addressed the issues in version 3.0 and the issues were assigned CVE-2026-50548 and CVE-2026-50549.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.