Code Execution Risk in Cursor IDE for macOS by Cursor
CVE-2026-73217

7.7HIGH

Key Information:

Vendor

Cursor

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73217?

Cursor IDE for macOS had a vulnerability that permitted an agent in Auto-Run Sandbox mode to swap the virtual environment's Python executable with a malicious wrapper. This exploitable weakness enabled the malicious wrapper to execute commands with user privileges outside the sandbox, potentially leading to unauthorized modifications of files and unauthorized application launches. This security issue has been addressed in version 3.1.2, ensuring enhanced protection against such risks.

Affected Version(s)

cursor < 3.1.2

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.