Skip to content

Critical Cursor IDE Flaws Let Attackers Execute Code via Zero

Gbhackers Divya July 2, 2026

Two significant remote code execution (RCE) vulnerabilities in the widely used Cursor ID expose developers to zero-click attacks driven by prompt injection. These vulnerabilities, tracked as CVE-2026-50548 and CVE-2026-50549, collectively known as “DuneSlide,” carry a CVSS score of 9.8. They demonstrate how development environments powered by large language models (LLMs) can unintentionally increase the attack […]

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (1)

Vulnerabilities (1)