Opening SecureFlowDuneSlide: Two Cursor Sandbox Escapes to Unsandboxed RCE
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Cato AI Labs aidefend-sf0034

DuneSlide: Two Cursor Sandbox Escapes to Unsandboxed RCE

  • Autonomous Agents
  • Tool Integrations & MCP
  • System Compromise & RCE

CVE-2026-50548 and CVE-2026-50549 are independent Cursor 2.x flaws. Poisoned MCP or web-search content can steer the agent through either an out-of-project working directory or a write-only symlink. Both paths can overwrite the cursorsandbox helper so subsequent commands run without the intended terminal sandbox. Cursor 3.0, released April 2, 2026, fixes both issues.

Mapped threat techniques

  • AML.T0051.001 LLM Prompt Injection: Indirect
  • AML.T0053 AI Agent Tool Invocation
  • AML.T0107 Exploitation for Defense Evasion
  • AML.T0050 Command and Scripting Interpreter

Source