we_are_coded.by CODE · The world, decoded
БГ
Cursor

Researchers showed how Cursor's AI agent could execute code on your machine with one hidden prompt

Cato NetworksSecurity

CVE-2026-50548 and CVE-2026-50549, both CVSS 9.8: a hidden instruction in one resource was enough to make Cursor's agent write outside its sandbox and execute commands. Patched in Cursor 3.0. No data on real attacks so far.

In short
  • Cato Networks disclosed (1 July) two critical vulnerabilities in Cursor (CVE-2026-50548/50549, CVSS 9.8).
  • Zero-click prompt injection: hidden text makes the agent write outside the sandbox and execute code; patched in Cursor 3.0.
  • Lesson: keep agents on a short leash - allowlist commands, sandbox, minimum rights; every piece of text an agent reads is a potential command.
Checked on6 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Researchers from Cato Networks (a cybersecurity firm) found two critical holes in the AI editor Cursor. The hole isn't the news. The news is the class of risk that comes bundled with every agent.

The facts: on 1 July Cato Networks published two independent critical vulnerabilities in Cursor - CVE-2026-50548 and CVE-2026-50549, both scored CVSS 9.8. The mechanism is 'zero-click prompt injection': hidden instructions in a dependency or resource the agent reads make it write a file outside its sandbox (through swapping the working directory and a weakness in symlink handling (a file that points to another file)). That turns an isolated command into code execution on the machine itself. Affected are the Cursor 2.x versions with automatic terminal execution; the issue is patched in Cursor 3.0 (2 April). No confirmed real attacks - this is responsible disclosure by researchers. Primary source: Cato Networks.

I won't dress it up: this is the new risk class of agents. They don't breach you. They breach the tool you gave hands and a keyboard to. If an agent can write files and run commands, every piece of text it reads - code, a document, a web page - becomes a potential command to it.

That's why agents get kept on a short leash: an allowlist of commands, a sandbox, zero blind execution. The benefit of the AI editor is real. Give it minimum rights and watch what it sends out. This hole is patched. The next one might still be open when you run into it.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cato Networks - DuneSlide: Two Critical RCE Vulnerabilities in Cursor
Original: https://wearecoded.com/en/articles/cursor-duneslide-rce-disclosure.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news