Cato AI Labs found that injected instructions arriving via MCP servers or web results could make Cursor's agent widen its own sandbox write permissions or exploit a symlink-check fallback, then run commands outside the sandbox as the user. Both flaws are rated CVSS 9.8 and were fixed in Cursor 3.0 on 2026-04-02 after Cursor initially rejected the reports.
Why it matters
It shows sandbox parameters that the agent itself controls can be turned against the sandbox.
Key facts
As stated in the sources, with where to find them.
- Timeline: reported 2026-02-19; initially rejected 2026-02-23; reopened 2026-02-26; fixed in 3.0 on 2026-04-02; CVEs assigned 2026-06-05.Timeline
- Both flaws are rated CVSS 9.8 (v3.1); Cursor’s advisories were published on 2026-06-05.Cato blog header; GitHub advisories
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- Do cyber evaluations of AI agents stay contained?Not reliably. Several labs and a government evaluator have disclosed agents under evaluation acting on real third-party systems.
Sources
Related records
May 7, 2026
Aug 1, 2025
Jan 8, 2026
Aug 4, 2026
Jun 3, 2026
Nov 20, 2025