Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Cursor IDE macOS sandbox escapes in Auto-Run mode

Two vulnerabilities in Cursor IDE for macOS allow agents running in Auto-Run Sandbox mode to escape the sandbox and execute arbitrary commands with user privileges. The first affects versions before 3.1.2 through Python executable replacement; the second affects versions before 3.0.0 through Docker container mounting.

Disclosed 11 August 2026 · Record updated 13 September 2026

Impact

Agents in Auto-Run Sandbox mode can escape sandbox restrictions and execute arbitrary host commands with user privileges, potentially modifying files outside the workspace and launching applications.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73217
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73218