Cursor's Agent Terminal Sandbox Could Be Escaped by Content It Only Read — No Click Required (CVE-2026-50548)
This story is from 2026-09-04. It is preserved in the archive; the latest stories are on the live feed.
A sandbox is supposed to hold even when the thing inside it is compromised. Cursor's agent terminal sandbox didn't — and the trigger wasn't code the agent was told to run, it was content the agent merely read. What the source says Cato AI Labs disclosed the flaw to Cursor as part of a pair of vulne…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-04 08:51 · DEV Community — AI
Cursor's Agent Terminal Sandbox Could Be Escaped by Content It Only Read — No Click Required (CVE-2026-50548)