Dev.to
7/1/2026
Cursor AI Editor Patched Critical Sandbox Escape Flaws
Short summary
Cursor AI Editor shipped patches (CVE-2026-50548, CVE-2026-50549) in version 3.0 for critical sandbox escape flaws allowing attackers to inject instructions via MCP tools, potentially exposing developer credentials on Fortune 500 machines. Both flaws rated 9.8/10 CVSS; updates are live and responsible disclosure occurred July 1. Developers should upgrade immediately, restrict MCP servers, avoid sudo, and harden shell startup files with append-only permissions.
- •Two critical CVEs (9.8/10 CVSS) in Cursor pre-3.0 allow sandbox escape via prompt injection through MCP tools or web results
- •Patches shipped April 2 in Cursor 3.0; responsible disclosure published July 1 covering both working directory and symlink bypass techniques
- •Mitigation: upgrade to 3.0+, restrict MCP server scope, avoid sudo, and apply append-only permissions to shell startup files
Generated with AI, which can make mistakes.
Is this a good recommendation for you?


