Skip to content
Vulnerability intelligence

CVE-2026-50549

CVE-2026-50548 and CVE-2026-50549 — dubbed DuneSlide — let a prompt injection escape Cursor's sandbox and execute arbitrary commands with developer privileges. More than half the Fortune 500 use Cursor. Every version before 3.0 was vulnerable.

2026