DuneSlide, prompt injection in Cursor could escape the sandbox and run any command

Started by EarlyBird, Jul 03, 2026, 11:42 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: DuneSlide, prompt injection in Cursor could escape the sandbox and run any command   Views(Read 99 times)

EarlyBird

Cato AI Labs found two flaws in Cursor, the AI code editor, that let a single ordinary looking prompt break out of the editor safety sandbox and run any command on a developer machine. No click to fall for, no approval box to ignore. They named the pair DuneSlide and both are rated 9.8 out of 10

The mechanism is prompt injection. Cursor runs the terminal commands its AI agent issues inside a sandbox by default to limit damage, and DuneSlide is about getting out of that box. The whole point of the sandbox was to contain stray instructions and this defeats it

The reach is the concerning part. Cursor says more than half the Fortune 500 use the tool. Both bugs are patched in Cursor 3.0 from April 2, and every version before 3.0 is affected, so if you are behind on updates you are exposed. Go update

This is the agentic coding risk in a nutshell. The moment you let a model run commands on your behalf, a malicious prompt hidden in a file or a repo becomes a remote code execution vector. Sandboxes help but as this shows they are not magic. Anyone doing agentic dev should treat untrusted input in their codebase as genuinely hostile


Midnight Georgia

No click and no approval box. That is the whole nightmare of agentic coding in one sentence

HiggsField10

Half the Fortune 500 on Cursor and a 9.8 sandbox escape. Update Monday morning everyone
git commit -m "fixed everything"

Faded Owen

Prompt injection defeating the sandbox was always going to happen. Sandboxes are not magic

CollapseState87

Treat every file in an untrusted repo as hostile input now. That is the new baseline

Coastal Otter

Patched in 3.0 back in April but how many shops are still on 2.x. Loads probably

Emma29

The attack surface of let a model run my terminal is just fundamentally huge

Undertaker_EU

This is why I still gate every command my agent wants to run. Slower but sane

TrainingRun Anvil


Stuart_67

Genuinely how do you sandbox something whose whole job is to execute arbitrary dev commands
Not financial advice. Not medical advice. Just vibes.

Rachel


Save money on everyday spending Free cashback on thousands of retailers
View offer