CVE-2026-73218: Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in A
Summary
Cursor is a code editor designed for AI-assisted programming. In versions before 3.0.0 on macOS, a security flaw allowed an agent running in Auto-Run Sandbox mode to launch a privileged container (a lightweight virtual environment) that could access the user's home directory and run commands on the computer without asking for permission first.
Solution / Mitigation
This issue is fixed in version 3.0.0.
Vulnerability Details
EPSS: 0.0%
August 11, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73218
First tracked: August 11, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%