Junglewise Threat Intelligence

CVE-2026-73217: Cursor IDE sandbox escape via malicious Python wrapper

CVE-2026-73217 · Severity: info · Published 2026-08-11

Executive brief

Cursor is an AI-powered code editor for macOS. A malicious agent running in the sandboxed Auto-Run mode can replace Python executables with wrapper scripts that execute arbitrary commands when the Python extension invokes them outside the sandbox. An attacker with access to the sandbox can modify files on the user's system and launch applications with the user's full privileges.

Technical details

This is a sandbox escape vulnerability in Cursor IDE for macOS. The vulnerable component is the Auto-Run Sandbox, which fails to prevent a sandboxed agent from modifying Python virtual environments located outside the sandbox boundary. An attacker controlling code running in Auto-Run Sandbox mode can replace the Python interpreter executable with a malicious wrapper script. When the Microsoft Python extension later invokes this wrapper outside the sandbox, the wrapper executes arbitrary shell commands with the user's privileges. No authentication bypass is required; the attack relies on the sandbox's insufficient isolation of the Python interpreter. The vulnerability affects versions prior to 3.1.2 and is fixed in version 3.1.2 or later.

Affected products

  • Cursor Cursor IDE before 3.1.2

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: patched: Version 3.1.2 released
  • 2026-08-11: advisory

References

Related threats