DuneSlide: How a Prompt Injection Became Full RCE in Cursor IDE
Cato AI Labs found two 9.8 CVSS flaws in Cursor's terminal sandbox — CVE-2026-50548 and CVE-2026-50549 — that let a poisoned MCP response or search result silently escape to full remote code execution. Neither requires a click.