A critical vulnerability in the Cursor IDE, tracked as CVE-2026-26268, has been disclosed, allowing arbitrary code execution (RCE) on developers' machines. The flaw arises from the interaction between Cursor's AI agent…
Cato AI Labs disclosed two critical remote code execution (RCE) vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549. These vulnerabilities allow attackers to exploit zero-click prompt injection,…
Researchers have identified critical remote code execution (RCE) vulnerabilities in AI inference engines utilized by Meta, Nvidia, and Microsoft. These flaws could potentially allow attackers to exploit the frameworks,…
Critical remote code execution (RCE) vulnerabilities have been identified in AI inference frameworks from Meta, Nvidia, Microsoft, and open-source projects like vLLM and SGLang. These flaws arise from unsafe code reuse,…
Proofpoint Threat Research has identified a vulnerability named CursorJack that exploits deeplinks in the Cursor Integrated Development Environment (IDE). This method allows attackers to potentially execute arbitrary…
Security researchers have identified a vulnerability in Cursor, an AI-powered code editor, that allows rogue Model Context Protocol (MCP) servers to inject malicious code into its internal browser. This exploit can…
Hackers are exploiting a critical vulnerability in Cursor, an AI-powered code editor, by using compromised Model Context Protocol (MCP) servers to inject malicious code. This attack allows the rogue servers to…