BREAKING
Two Critical Cursor Flaws Below 3.0
0
CVSS score
0
CVEs chained
0
Fixed in version
Zero-Click Injection Chain
1Hidden text via MCP or search
2Indirect prompt injection
3User enters normal prompt
4Sandbox escape and RCE
Two Different Entry Points
CVE-2026-50548working_directory
Manipulates run_terminal_cmd
Overwrites sandbox helper
Sandbox disabled
CVE-2026-50549symlink fallback
Canonicalization failure
Writes outside project
Helper overwritten
Used by Over Half the Fortune 500
Update to Cursor 3.0 Now
AI NEWS BLITZ
Two critical bugs in the AI editor Cursor could let attackers escape the sandbox and run code.