CursorGHSA-p9g2-cr55-cw9c
Sandbox escape via tampered Python virtual environments
HighCVE-2026-73217 · Published Jul 14, 2026 · updated Aug 11, 2026
Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment’s Python executable with a malicious wrapper. When the Microsoft Python extension invokes that interpreter outside the sandbox, the wrapper can execute arbitrary host commands with the user’s privileges, including modifying files outside the workspace and launching applications.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor Product | < 3.1.2 | 3.1.2 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | Sandbox escape via launching privileged containers | High | No fix yet |
| Jul 6 | Cloud Agent Browser Sandbox Escape | High7.7 | Fixedon03/31/2026 |
| Jun 5 | Cursor Desktop sandbox escape via agent-controlled working directory | Critical | 3.0 |
| Jun 5 | Cursor Desktop sandbox escape via symlink and failed path canonicalization | Critical | 3.0 |
| May 21 | Cursor Desktop sandbox escape via Claude hook configuration | High8.5 | 3.0.0 |
| Mar 9 | Arbitrary Code Execution via Prompt Injection and Whitelist Bypass | High | 2.0 |