Letsdatascience Critical RCE Vulnerabilities in Cursor IDE Enable Zero-Click Prompt Injection Attacks
Article Content
- •CVE-2026-50548 and CVE-2026-50549 allow zero-click RCE via prompt injection.
- •The vulnerabilities exploit flaws in Cursor IDE's sandboxing mechanisms.
- •A patch was released in April 2026; unpatched systems remain at risk.
Cato AI Labs disclosed two critical remote code execution (RCE) vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549. These vulnerabilities allow attackers to exploit zero-click prompt injection, enabling arbitrary code execution without user interaction. The flaws arise from improper handling of the working directory and symlink resolution within Cursor's sandboxed environment. This attack vector is particularly dangerous as it can be triggered by benign prompts that ingest malicious content from untrusted sources. The vulnerabilities have a CVSS score of 9.8, indicating a critical severity level. Cursor IDE is widely used, with over half of Fortune 500 companies relying on it. A patch was released in April 2026, but systems not updated remain vulnerable. Users are advised to avoid processing untrusted content until a confirmed fix is implemented.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (37)
Following this threat?
Track Jadepuffer, Cato AI Labs and CVE-2026-10591 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…