Skip to content
CursorGHSA-p9g2-cr55-cw9c

Sandbox escape via tampered Python virtual environments

HighCVE-2026-73217 · Published Jul 14, 2026 · updated Aug 11, 2026

Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment’s Python executable with a malicious wrapper. When the Microsoft Python extension invokes that interpreter outside the sandbox, the wrapper can execute arbitrary host commands with the user’s privileges, including modifying files outside the workspace and launching applications.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
< 3.1.23.1.2
Details and references

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.