DuneSlide: Two Cursor Bugs Turn a Prompt Into a Shell
A pair of 9.8-rated flaws in the AI code editor let a single crafted prompt escape the sandbox and execute arbitrary commands, no user approval required.

Key points
- Two critical flaws in Cursor, tracked as CVE-2026-50548 and CVE-2026-50549, carry a CVSS score of 9.8 (Cursor's own assessment: 9.3).
- Cato AI Labs named the pair DuneSlide; exploiting them requires no click, no malicious extension, and no approval dialog.
- A single ordinary-looking prompt is enough to break out of the editor's safety sandbox and run arbitrary commands on the host machine.
- The most realistic attack path is indirect: a payload hidden in a README, a dependency comment, or any file the agent fetches.
- A patch is expected from Cursor; users should confirm the version number, not just the update prompt.
What do the DuneSlide bugs actually do?
Cursor, the AI-first code editor many developers now leave running all day, has picked up two critical flaws that collapse the distance between "model reads a file" and "attacker runs code on your laptop." Cato AI Labs found them, named them DuneSlide, and rates both CVE-2026-50548 and CVE-2026-50549 at 9.8 on CVSS.
The exploit doesn't need a click, a rogue extension, or any approval dialog to bypass. One ordinary-looking prompt, the kind you'd paste into the chat pane without a second thought, is enough to escape the safety sandbox and execute arbitrary commands on the host.
This is the AI-agent version of a classic sandbox escape, with the language model playing the role of a very obliging confused deputy. The model has permission to run tools; the prompt tricks it into running the wrong ones with the wrong arguments. Guardrails that should require human confirmation simply don't fire.
Should you worry about prompt injection specifically?
I've been careful in this column about calling every LLM misbehaviour a "vulnerability." DuneSlide clears the bar. The delivery vector is data the model was designed to read, and the outcome is code execution. That's a security bug, not a policy tuning issue.
The realistic attack path is indirect injection. Attackers don't need your keyboard. They need their payload in something Cursor will chew on: a README in a dependency, a comment in an issue, documentation the agent fetches. Anything the model treats as input is a potential trigger. For developers running Cursor against untrusted repos, that threat model is uncomfortable.
We first covered this class of attack on 29 June, when malicious instructions buried in a repository's files were shown to hijack Claude Code and open a reverse shell on the developer's machine, no obvious malware required. DuneSlide lands in the same territory.
What should developers do right now?
Update Cursor to the patched build as soon as the vendor ships it, and confirm the version number, not just the update prompt. Beyond that, treat every repo, dependency, or web-fetched context you point an agent at as untrusted input, exactly as you would a file uploaded to a web app.
Longer term, DuneSlide is another data point in an argument the AI-tools industry keeps trying to skip. Agentic editors need the same capability boundaries browsers spent twenty years grinding out. A lot of them are shipping right now with something closer to a 1998 ActiveX security model, dressed in a nicer UI.
Expect more of these.



