Signal

DuneSlide: the Cursor flaws that let a web search result run code on a developer's laptop, no click required

Cato Networks disclosed two critical, zero-click remote-code-execution flaws in the Cursor AI code editor — CVE-2026-50548 and CVE-2026-50549, both CVSS 9.8 — patched in Cursor 3.0 back in April but only assigned CVE numbers in June, and Cato says the underlying sandbox-escape pattern isn't unique to Cursor.