Cursor Flaws Let Prompt Injection Overwrite Its Sandbox and Run Code
Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
Reader edition
Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
A routine page fetch in older Kiro builds could end with attacker-controlled code running through a rewritten MCP configuration.
The botnet gives AI workbenches priority in its scan queue, then searches compromised hosts for cloud credentials, service-account tokens, and callable tools.
A sponsored search result sent victims through a public page on claude.ai before delivering a fake desktop installer.