CVE-2026-50548 and CVE-2026-50549, both CVSS 9.8: a hidden instruction in one resource was enough to make Cursor's agent write outside its sandbox and execute commands. Patched in Cursor 3.0. No data on real attacks so far.
- Cato Networks disclosed (1 July) two critical vulnerabilities in Cursor (CVE-2026-50548/50549, CVSS 9.8).
- Zero-click prompt injection: hidden text makes the agent write outside the sandbox and execute code; patched in Cursor 3.0.
- Lesson: keep agents on a short leash - allowlist commands, sandbox, minimum rights; every piece of text an agent reads is a potential command.
Researchers from Cato Networks (a cybersecurity firm) found two critical holes in the AI editor Cursor. The hole isn't the news. The news is the class of risk that comes bundled with every agent.
I won't dress it up: this is the new risk class of agents. They don't breach you. They breach the tool you gave hands and a keyboard to. If an agent can write files and run commands, every piece of text it reads - code, a document, a web page - becomes a potential command to it.
That's why agents get kept on a short leash: an allowlist of commands, a sandbox, zero blind execution. The benefit of the AI editor is real. Give it minimum rights and watch what it sends out. This hole is patched. The next one might still be open when you run into it.