Critical Cursor AI Code Editor Flaws Could Lead to OS Level Remote Code Execution
Cursor AI code editor has sandbox escape flaws that let attackers run code on the host OS with no user clicks.
The DuneSlide issues allow zero-click prompt injection that breaks out of the editor sandbox and executes arbitrary commands on the underlying system.
The flaws affect Cursor Desktop versions before 3.0. Cursor 3.0 includes the fixes.
Attacks chain malicious prompts directly into OS-level execution without additional user interaction.
