Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
The Hacker News
1 month ago

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

By info@thehackernews.com (The Hacker News)

Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on a developer's computer. There is no click to fall for and no approval box to ignore. Cato AI Labs found the pair and named them DuneSlide. They are tracked as CVE-2026-50548 and CVE-2026-50549, both rated 9.8 out of 10 (or 9.3

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.