#rce

3 articles

Agentjacking: Fake Sentry Bug Hijacks 100+ AI Coding Agents

Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code…

Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection

Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt inject…

Beware: Cursor CLI Ran Your Attacker's Code Before You Clicked 'Trust' — Pre-Trust RCE in Worktree Setup

Cursor's CLI agent executed arbitrary commands from a cloned repository's .cursor/worktrees.json BEFORE the workspace trust prompt…