Cursor IDE Vulnerabilities Let Prompt Injection Escape the Sandbox
Two critical Cursor IDE vulnerabilities, dubbed DuneSlide, let prompt injection break the editor’s command sandbox with no click required. Both are fixed in Cursor 3.0.
Two critical Cursor IDE vulnerabilities, dubbed DuneSlide, let prompt injection break the editor’s command sandbox with no click required. Both are fixed in Cursor 3.0.
CVE-2026-12957 in Amazon Q is the third MCP auto-execution vulnerability in three AI coding tools. The pattern reveals a shared design failure, not just a single vendor mistake.