Critical Cursor Vulnerabilities Allow Prompt Injection to Escape Sandbox and Execute Commands
Two critical vulnerabilities, DuneSlide (CVE-2026-50548 and CVE-2026-50549), discovered in the AI code editor Cursor, enable prompt injection attacks to bypass security sandboxes and execute arbitrary commands on developer machines.