Cato AI Labs
aidefend-sf0034
DuneSlide: Two Cursor Sandbox Escapes to Unsandboxed RCE
- Autonomous Agents
- Tool Integrations & MCP
- System Compromise & RCE
CVE-2026-50548 and CVE-2026-50549 are independent Cursor 2.x flaws. Poisoned MCP or web-search content can steer the agent through either an out-of-project working directory or a write-only symlink. Both paths can overwrite the cursorsandbox helper so subsequent commands run without the intended terminal sandbox. Cursor 3.0, released April 2, 2026, fixes both issues.
Mapped threat techniques
AML.T0051.001LLM Prompt Injection: IndirectAML.T0053AI Agent Tool InvocationAML.T0107Exploitation for Defense EvasionAML.T0050Command and Scripting Interpreter