Chronicle/Attacks & incidents

DuneSlide: two Cursor flaws let prompt injection escape the agent sandbox (CVE-2026-50548/50549)

AttackVulnerability disclosureSignificance assistant-drafted

Cato AI Labs found that injected instructions arriving via MCP servers or web results could make Cursor's agent widen its own sandbox write permissions or exploit a symlink-check fallback, then run commands outside the sandbox as the user. Both flaws are rated CVSS 9.8 and were fixed in Cursor 3.0 on 2026-04-02 after Cursor initially rejected the reports.

Why it matters

It shows sandbox parameters that the agent itself controls can be turned against the sandbox.

Key facts

As stated in the sources, with where to find them.

  • Timeline: reported 2026-02-19; initially rejected 2026-02-23; reopened 2026-02-26; fixed in 3.0 on 2026-04-02; CVEs assigned 2026-06-05.Timeline
  • Both flaws are rated CVSS 9.8 (v3.1); Cursor’s advisories were published on 2026-06-05.Cato blog header; GitHub advisories

Findings that cite this record

Key questions this bears on

Sources

Related records