Cato AI Labs disclosed two critical remote code execution (RCE) vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549. These vulnerabilities allow attackers to exploit zero-click prompt injection,…
A vulnerability in AWS Kiro, an AI-powered IDE, was disclosed on July 21, 2026, allowing attackers to execute code on a developer's machine through a hidden line of text on a webpage. The flaw bypasses Kiro's…
A security flaw in Cursor's CLI agent enables cloned repositories to execute arbitrary commands on a developer's machine before trust verification. This vulnerability affects users who start the agent with the worktree…