Cursor Flaws Let Prompt Injection Overwrite Its Sandbox and Run Code
Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
Read article →Reader view
Choose the default article length.
Software vulnerabilities, dependencies, and application security.
Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
Read article →A routine page fetch in older Kiro builds could end with attacker-controlled code running through a rewritten MCP configuration.
Read article →