LOWVulnerability

CVE-2026-73218

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges without an additional permission prompt. This issue is fixed in version 3.0.0.

Properties

epss_score
0.00818
cve_id
CVE-2026-73218
published_at
2026-08-11T18:18:27.320
last_modified
2026-09-09T20:58:37.713
epss_percentile
0.54993

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Privilege Management

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73218 — Ninja Signal Threat Intelligence | Ninja Signal