DuneSlide flaws let a prompt injection run code on developers' machines through Cursor
Cato Networks disclosed two critical Cursor code-editor flaws, rated 9.8 out of 10, that let a prompt injection escape the sandbox and run code with no click; a fix shipped in April.
Cato Networks disclosed two critical remote-code-execution vulnerabilities in the Cursor AI code editor on July 1, 2026. A single prompt-injected instruction can escape Cursor’s terminal sandbox and run arbitrary commands on a developer’s machine with no click or approval required. The flaws, dubbed DuneSlide, are both rated 9.8 out of 10 on the CVSS 3.1 severity scale.
The attack matters because it needs no user action. A malicious instruction hidden in content an AI agent merely reads – a response from a connector using the Model Context Protocol, or a web search result – is enough to break out, the security firm’s Cato AI Labs said. That turns prompt injection into a direct path to code execution, not just a way to coax bad text out of a model.
The two bugs are tracked as CVE-2026-50548 and CVE-2026-50549, assigned identifiers on June 5, 2026.
The fix already exists. Cato reported the flaws to Cursor maker Anysphere on February 19; the report was initially rejected on February 23 before being reopened, and a fix shipped in the Cursor 3.0 release on April 2. Every Cursor version before 3.0 remains vulnerable, so developers on older builds are exposed until they upgrade.
The severity scores and attack description come from Cato’s own research and have not been independently reproduced here; Anysphere has not published a first-party statement on DuneSlide. Because the patch predates public disclosure, the practical risk now rests on how many teams still run pre-3.0 Cursor.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
