Skip to content
CursorGHSA-v4xv-rqh3-w9mc

Sandbox escape via launching privileged containers

HighCVE-2026-73218 · Published Jul 14, 2026 · updated Aug 11, 2026

Docker Desktop VirtioFS escape: Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to escape the sandbox when Docker Desktop and the Dev Containers CLI are installed. Malicious agent instructions can launch a privileged container and mount Docker’s `virtiofs0`, granting read/write access to the user’s home directory and enabling host command execution with the user’s privileges without an additional permission prompt.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor
Product
all versionsNo fix yet
Details and references

More Cursor advisories

All Cursor

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.