
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73217 is a sandbox escape vulnerability in Cursor IDE for macOS that allows an AI agent operating in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper, enabling arbitrary host command execution outside the sandbox. It affects all Cursor versions prior to 3.1.2 and was published on August 11, 2026. The vulnerability was reported by researcher Danus365 and disclosed via GitHub Security Advisory GHSA-p9g2-cr55-cw9c (GitHub Advisory). It carries a CVSS v4.0 base score of 7.7 (High) (Feedly).
The root cause is classified as CWE-693 (Protection Mechanism Failure) — the Auto-Run Sandbox mode in Cursor IDE for macOS fails to adequately restrict an agent's ability to modify files within Python virtual environments (GitHub Advisory). An agent running inside the sandbox can overwrite or replace the Python executable within a virtual environment with a malicious wrapper script. When the Microsoft Python extension subsequently invokes that interpreter — a process that occurs outside the sandbox boundary — the wrapper executes arbitrary host-level commands with the privileges of the logged-in user (GitHub Advisory). This attack requires the presence of a Python virtual environment in the workspace and passive user interaction (e.g., the user triggering the Python extension), aligning with the CVSS v4.0 attack requirements of AT:P and UI:P (Feedly).
Successful exploitation allows an attacker-controlled AI agent to execute arbitrary commands on the host macOS system with the user's full privileges, bypassing the intended sandbox isolation (GitHub Advisory). This can result in high confidentiality, integrity, and availability impact to the vulnerable system, including reading sensitive files, modifying files outside the workspace, and launching arbitrary applications (Feedly). The attack is scoped to the host system (no lateral movement to adjacent systems is indicated), but the ability to run arbitrary commands with user privileges represents a significant risk of data exfiltration and persistent compromise.
As of the disclosure date, there is no evidence of in-the-wild exploitation, and the SSVC exploitation status is listed as "none" (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.31%, indicating a low probability of exploitation in the near term (Feedly). No public proof-of-concept exploit code has been identified. Exploitation is not fully automatable, as it requires passive user interaction (triggering the Microsoft Python extension) and the presence of a Python virtual environment in the workspace.
.venv/, env/, or venv/) and its Python executable (e.g., .venv/bin/python)..venv/bin/python, env/bin/python); Python executable replaced with a shell script or non-standard binary; presence of unexpected scripts in virtual environment bin/ directories.bash, curl, osascript, open) that are not typical Python interpreter invocations; processes launched with user privileges performing file operations outside the workspace directory.Cursor has released version 3.1.2, which fixes this vulnerability; users should update immediately (GitHub Advisory). As a workaround prior to patching, users can disable Auto-Run Sandbox mode or avoid using Python virtual environments within Cursor workspaces when running AI agents. Additionally, users should review and restrict agent permissions and be cautious about enabling Auto-Run mode with untrusted AI agents or in sensitive development environments.
The vulnerability was reported by researcher Danus365 and disclosed through GitHub's coordinated security advisory process (GitHub Advisory). No significant broader media coverage, vendor statements beyond the advisory, or notable social media commentary has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."