Tools AI Risk Radar ai-incident-0063
Incident record
DuneSlide: critical Cursor AI editor flaws allow OS-level code execution
- Severity
- Critical
- Status
- Patched
- Type
- Prompt Injection
- Target
- Cursor
- Actor
- researcher
- CVE
- CVE-2026-50548
What happened
Cato Networks disclosed two critical flaws it dubbed DuneSlide (CVSS 9.8) in the Cursor AI code editor, in which a prompt injection could escape the tool's sandbox and run commands on the underlying operating system. The bugs abused Cursor's automatic terminal execution and were fixed in Cursor 3.0. No in-the-wild exploitation was reported.
Sources
- SecurityWeek (Cato Networks)www.securityweek.com/critical-cursor-ai-ide-flaws-could-lead…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026