Researchers discover prompt injection vulnerabilities in Cursor IDE enabling remote code execution
Cato Networks researchers discovered two vulnerabilities (CVE-2026-50548 and CVE-2026-50549) in the Cursor AI-enabled IDE that allow attackers to break out of the command execution sandbox and achieve remote code execution through prompt injection, according to CSO Online. The flaws require no prior user privileges or specific user interaction, revealing what researchers characterize as a native flaw in large language models and AI-assisted development environments.
Topics
Sources
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.