---
id: CVE-2026-73218
title: Cursor is a code editor built for programming with AI
summary: >-
  Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor
  IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker
  Desktop and the Dev Containers CLI are installed, to launch a privileged
  container …
severity: none
cwe:
  - CWE-269
published: '2026-08-11'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:58:37.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73218'
references:
  - url: 'https://github.com/cursor/cursor/security/advisories/GHSA-v4xv-rqh3-w9mc'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00634
epssPercentile: 0.48113
ingestedAt: '2026-09-09T21:22:45.529Z'
---

## Overview

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges without an additional permission prompt. This issue is fixed in version 3.0.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
