Critical Cursor Flaws Enable Zero-Click Sandbox Escape via Prompt Injection
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
CVE-2025-54135, known as CurXecute, is a vulnerability in Cursor discovered by Aim Security. A planted Slack message rewrites Cursor's ~/.cursor/mcp.json config and…
A Git-hook sandbox escape vulnerability in Cursor, reported by Novee under coordinated disclosure and fixed in Cursor 2.5 on February 13, 2026.
CVE-2023-4863 is a heap buffer overflow vulnerability in the WebP image format library, which can be exploited for browser-based attacks. It was…
Citrix has released security updates to address six vulnerabilities in NetScaler ADC and NetScaler Gateway, including flaws that could allow arbitrary file…
An insufficient input validation vulnerability in Citrix NetScaler ADC and Gateway when configured as a SAML IDP, leading to memory overread. CVSS…
A memory overflow vulnerability in Citrix NetScaler ADC and Gateway when configured as a Gateway or AAA virtual server, leading to denial-of-service.…
Multiple memory overflow vulnerabilities in Citrix NetScaler ADC when configured as an LB of type Oracle, DNS Proxy, or DNS recursive resolver,…
An external control of file name vulnerability in Citrix NetScaler ADC and Gateway allowing unauthenticated arbitrary file read when management access is…
An insufficient input validation vulnerability in Citrix NetScaler ADC and Gateway when TCP TimeStamp is enabled, leading to memory overread. CVSS score…