DuneSlide: two CVSS 9.8 Cursor flaws turned prompt injection into full host and SaaS workspace compromise
At a Glance
- Serious damage. Customer data affected, security incident, or financial losses $10k–$100k.
Independent project · aggregated from public reports and may be unverified — see the primary source below · not affiliated with or endorsed by any company or product named.
What Happened
Cato AI Labs disclosed CVE-2026-50548 and CVE-2026-50549, both rated CVSS 9.8, affecting Cursor IDE 2.x with automatic terminal command execution. The first let the agent set the working_directory parameter on run_terminal_cmd to a non-default path, which Cursor added to the allowed-write list without validation, permitting writes to the sandbox executable itself. The second was a symlink canonicalization fallback: when resolution failed, Cursor trusted the unvalidated symlink path, bypassing out-of-bounds write protections. Chained from attacker-controlled content the agent reads, such as an MCP-connected service or a web search result, either yielded zero-click sandbox escape and full system compromise on the host and connected SaaS workspaces. Cato reported the issues in February 2026, saw them initially rejected, escalated, and fixes were confirmed in Cursor 3.0.
Case Analysis
Verified Facts
- CVE-2026-50548 and CVE-2026-50549 were both rated CVSS 9.8
- One flaw let the agent widen its own allowed-write list via the working_directory parameter
- The initial report was rejected before escalation; fixes landed in Cursor 3.0
Not Publicly Confirmed
- Whether either flaw was exploited in the wild
Operational Lessons
- A sandbox fails the moment the agent controls its own policy parameters
- Symlink resolution must fail closed rather than fall back to trusting the unresolved path
Primary Source
DuneSlide: Two Critical RCE Vulnerabilities in Cursor (Cato Networks)catonetworks.com ↗Case Record
More Cases
Prompt injection reached host-level code execution in Microsoft Semantic Kernel through eval() and a stray annotation
Microsoft disclosed two vulnerabilities that turn prompt injection into host compromise in its Semantic Kernel agent framework, which has over 27,000 GitHub stars. CVE-2026-26030 affects the Python package before 1.39.4: the default in-memory vector store filter is a Python lambda executed with eval() on unsanitized model-controlled input, so an attacker could escape the template string, traverse Python's class hierarchy, bypass the AST blocklist validator and run arbitrary commands, demonstrated by launching calc.exe from a single prompt injection. CVE-2026-25592 affects the .NET SDK before 1.71.0: DownloadFileAsync was accidentally marked with a [KernelFunction] attribute, exposing it to the model with an entirely AI-controlled, unvalidated local file path, allowing writes to locations such as the Windows Startup folder and thus sandbox escape.
SearchLeak let a single click on a malicious link pull emails, files and MFA codes out of Microsoft 365 Copilot
Varonis Threat Labs disclosed CVE-2026-42824, a critical flaw in Microsoft 365 Copilot Enterprise Search. Clicking a single crafted link chained three bugs: injection of the URL parameter into the prompt, a rendering race condition, and abuse of Content Security Policy allowlisting to exfiltrate data through Bing's infrastructure. The attack could reach emails and calendar details, indexed SharePoint and OneDrive files, one-time and MFA codes, password-reset links, meeting notes and salary data. Because Copilot Enterprise is a managed service, tenant admins could not patch it themselves; Microsoft mitigated the flaw on its backend.
Cursor's command allowlist could be bypassed with shell built-ins, giving prompt injection a silent path to code execution
Pillar Security disclosed CVE-2026-22708 in Cursor. In Auto-Run Mode with an allowlist enabled, shell built-ins such as export, typeset, declare, readonly, unset and local were implicitly trusted by Cursor's server-side evaluator and executed without appearing in the allowlist or requiring approval, because they run inside the shell session rather than as separate binaries. An attacker delivering indirect prompt injection could silently poison environment variables and then trigger malicious code through trusted developer tools, producing both zero-click and one-click remote code execution. Pillar reported it in August 2025, Cursor acknowledged it as a systemic issue in September 2025, and the fix shipped in version 2.3 in January 2026, which now requires explicit approval for any command the parser cannot classify.