CVE-2026-73218

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges without an additional permission prompt. This issue is fixed in version 3.0.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 18:18

Updated : 2026-09-09 20:58


NVD link : CVE-2026-73218

Mitre link : CVE-2026-73218

CVE.ORG link : CVE-2026-73218


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management