BREAKING
Two Critical Cursor Flaws Below 3.0
0
CVSS score
0
CVEs chained
0
Fixed in version
Zero-Click Injection Chain
1
Hidden text via MCP or search
↓
2
Indirect prompt injection
↓
3
User enters normal prompt
↓
4
Sandbox escape and RCE
Two Different Entry Points
CVE-2026-50548
working_directory
●
Manipulates run_terminal_cmd
●
Overwrites sandbox helper
●
Sandbox disabled
CVE-2026-50549
symlink fallback
●
Canonicalization failure
●
Writes outside project
●
Helper overwritten
Used by Over Half the Fortune 500
Update to Cursor 3.0 Now
AI NEWS BLITZ
Two critical bugs in the AI editor Cursor could let attackers escape the sandbox and run code.