ainewsblitz.com

Breaking

Two Critical Flaws in Pre-3.0 Cursor Enable Sandbox Escape and Code Execution

  • Security
  • Software Dev & Coding
  • AI Agents

Two critical vulnerabilities in versions of the AI code editor Cursor prior to 3.0 could let attackers escape the terminal sandbox and run arbitrary commands on a developer's machine. Tracked as CVE-2026-50548 and CVE-2026-50549, both carry a Critical rating of CVSS 9.8 (9.3 under CVSS 4.0).

Continue reading

The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.

$20
Read this article
$29/month
Unlimited — all 9,955 articles, the full archive, and comprehension quizzes
Save 72%
$98/year
≈ $8.17/month
Unlimited, billed once a year