CursorGHSA-v4xv-rqh3-w9mc
Sandbox escape via launching privileged containers
HighCVE-2026-73218 · Published Jul 14, 2026 · updated Aug 11, 2026
Docker Desktop VirtioFS escape: Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to escape the sandbox when Docker Desktop and the Dev Containers CLI are installed. Malicious agent instructions can launch a privileged container and mount Docker’s `virtiofs0`, granting read/write access to the user’s home directory and enabling host command execution with the user’s privileges without an additional permission prompt.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor Product | all versions | No fix yet |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | Sandbox escape via tampered Python virtual environments | High | 3.1.2 |
| Jul 6 | Cloud Agent Browser Sandbox Escape | High7.7 | Fixedon03/31/2026 |
| Jun 5 | Cursor Desktop sandbox escape via agent-controlled working directory | Critical | 3.0 |
| Jun 5 | Cursor Desktop sandbox escape via symlink and failed path canonicalization | Critical | 3.0 |
| May 21 | Cursor Desktop sandbox escape via Claude hook configuration | High8.5 | 3.0.0 |
| Mar 9 | Arbitrary Code Execution via Prompt Injection and Whitelist Bypass | High | 2.0 |