Security researchers disclosed two critical vulnerabilities, dubbed ‘DuneSlide’ (CVE-2026-50548 and CVE-2026-50549), in the Cursor AI code editor. A single prompt-injected instruction hidden in content the coding agent reads, such as an MCP connector response or a web search result, could escape Cursor’s terminal sandbox and execute arbitrary commands on the developer’s machine with no click or approval required. One flaw overwrote the sandbox helper binary itself, while the other exploited a symlink resolution bug to write outside the project directory. Both bugs were reported in February 2026, patched in Cursor 3.0 (released April 2, 2026) before public disclosure, and no real-world exploitation was reported.