PulseAugur
EN
LIVE 15:49:16

Cursor IDE hit with two critical RCE vulnerabilities

Cursor, an AI-powered code editor used by over half of the Fortune 500, has disclosed two critical security vulnerabilities. These vulnerabilities, rated CVSS 9.8, allow for remote code execution through prompt injection without user interaction. The security flaws were detailed by DuneSlide and have raised concerns about the security of AI-integrated development tools. AI

IMPACT Highlights potential security risks in AI-integrated development tools, impacting enterprise adoption and trust.

RANK_REASON Disclosure of critical security vulnerabilities in an AI-powered code editor.

Read on r/cursor →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Cursor IDE hit with two critical RCE vulnerabilities

COVERAGE [1]

  1. r/cursor TIER_2 English(EN) · /u/docdavkitty ·

    50%+ of the Fortune 500 use Cursor. Two sandbox escapes (CVSS 9.8) were just disclosed — no click, no warning, full RCE

    <table> <tr><td> <a href="https://www.reddit.com/r/cursor/comments/1v1jriv/50_of_the_fortune_500_use_cursor_two_sandbox/"> <img alt="50%+ of the Fortune 500 use Cursor. Two sandbox escapes (CVSS 9.8) were just disclosed — no click, no warning, full RCE" src="https://external-prev…