YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0063

Incident record

DuneSlide: critical Cursor AI editor flaws allow OS-level code execution

Severity
Critical
Status
Patched
Type
Prompt Injection
Target
Cursor
Actor
researcher
CVE
CVE-2026-50548

What happened

Cato Networks disclosed two critical flaws it dubbed DuneSlide (CVSS 9.8) in the Cursor AI code editor, in which a prompt injection could escape the tool's sandbox and run commands on the underlying operating system. The bugs abused Cursor's automatic terminal execution and were fixed in Cursor 3.0. No in-the-wild exploitation was reported.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026