#sandbox-escape

2 articles

Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection

Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt inject…

Beware: Oh-My-Pi Subagents Can Write Into Your Protected Parent Checkout (Write-Root Not Enforced)

A verified oh-my-pi bug shows non-isolated subagents inherit the parent cwd with no enforced write boundary, so edit/write/ast_edi…