Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
ResearchcursorOur summary
Cato Networks reports two critical vulnerabilities in the AI code editor Cursor that could enable remote code execution on the host operating system by escaping the IDE’s sandbox. The issues are tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS 9.8), collectively referred to as DuneSlide, and they can be triggered through crafted prompts that abuse Cursor’s automatic terminal command execution and weaknesses in file path handling involving symbolic links. This matters because a malicious payload could move from an injected IDE action to unrestricted OS-level code execution.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.