๐Ÿ” CVE Alert

CVE-2026-73218

UNKNOWN 0.0

Cursor: Sandbox escape via launching privileged containers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges without an additional permission prompt. This issue is fixed in version 3.0.0.

CWE CWE-269
Vendor cursor
Product cursor
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for cursor cursor

Be the first to know when new unknown vulnerabilities affecting cursor cursor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cursor / cursor
< 3.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cursor/cursor/security/advisories/GHSA-v4xv-rqh3-w9mc