{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/cato-duneslide-cursor-sandbox-escape-2026/",
 "asOf": "2026-09-26",
 "id": "cato-duneslide-cursor-sandbox-escape-2026",
 "date": "2026-07-01",
 "datePrecision": "day",
 "title": "DuneSlide: two Cursor flaws let prompt injection escape the agent sandbox (CVE-2026-50548/50549)",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Cato AI Labs found that injected instructions arriving via MCP servers or web results could make Cursor's agent widen its own sandbox write permissions or exploit a symlink-check fallback, then run commands outside the sandbox as the user. Both flaws are rated CVSS 9.8 and were fixed in Cursor 3.0 on 2026-04-02 after Cursor initially rejected the reports.",
 "whyItMatters": "It shows sandbox parameters that the agent itself controls can be turned against the sandbox.",
 "actors": [
  "cato-networks",
  "cursor"
 ],
 "topics": [
  "sandbox-containment",
  "prompt-injection"
 ],
 "atlas": [
  "sandbox",
  "untrusted-content",
  "tools"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/",
   "publisher": "Cato Networks",
   "title": "DuneSlide: Two Critical RCE vulnerabilities",
   "date": "2026-07-01",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://github.com/cursor/cursor/security/advisories/GHSA-3v8f-48vw-3mjx",
   "publisher": "Cursor (GitHub security advisory)",
   "title": "GHSA-3v8f-48vw-3mjx (CVE-2026-50549)",
   "date": "2026-06-05",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://github.com/cursor/cursor/security/advisories/GHSA-3p48-7v9f-v5cw",
   "publisher": "Cursor (GitHub security advisory)",
   "title": "GHSA-3p48-7v9f-v5cw (CVE-2026-50548)",
   "date": "2026-06-05",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html",
   "publisher": "The Hacker News",
   "title": "Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands",
   "date": "2026-07-01",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Timeline: reported 2026-02-19; initially rejected 2026-02-23; reopened 2026-02-26; fixed in 3.0 on 2026-04-02; CVEs assigned 2026-06-05.",
   "locator": "Timeline"
  },
  {
   "fact": "Both flaws are rated CVSS 9.8 (v3.1); Cursor’s advisories were published on 2026-06-05.",
   "locator": "Cato blog header; GitHub advisories"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "indirect-prompt-injection",
  "sandbox-escape",
  "sandboxing-egress",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}