PatchSiren cyber security CVE debrief
CVE-2026-73217 cursor CVE debrief
CVE-2026-73217 debrief based on CVE Program and NVD records. The vulnerability affects Cursor IDE for macOS, allowing an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper, enabling arbitrary host commands with user privileges. This issue is fixed in version 3.1.2. Developers and security teams should assess exposure and take action to prevent exploitation, including verifying the integrity of the Python executable and virtual environments within the Cursor IDE.
- Vendor
- cursor
- Product
- Unknown
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-09-09
Who should care
Developers and security teams using Cursor IDE for macOS should assess exposure and take action to prevent exploitation. This includes verifying the integrity of the Python executable and virtual environments within the Cursor IDE, monitoring for suspicious activity, and implementing compensating controls to prevent exploitation. The vulnerability has a high CVSS score and severity, and affected product deployments should be identified and remediated as a
Why it matters
CVE-2026-73217 is a high-severity vulnerability in Cursor IDE for macOS, allowing arbitrary host commands with user privileges. Developers and security teams should assess exposure and upgrade to version 3.1.2 or later.
- Potential for arbitrary host commands with user privileges, allowing modifying files outside the workspace and launching applications
- Need for verification of Cursor IDE version and virtual environment integrity
- Potential for exploitation requires upgrading to version 3.1.2 or later
Technical summary
CVE-2026-73217 is a high-severity vulnerability in Cursor IDE for macOS, allowing an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper, enabling arbitrary host commands with user privileges. The issue is fixed in version 3.1.2. The vulnerability has a CVSS score of 7.7 and a severity of HIGH. The affected product is Cursor IDE for macOS, and the vulnerability requires upgrading to version 3.1.2 or later. The vulnerability allows arbitrary host commands with user privileges, including modifying files outside the workspace and launching applications.
Defensive priority
High priority for developers and security teams using Cursor IDE
Recommended defensive actions
- Developers and security teams should assess exposure and upgrade to Cursor IDE version 3.1.2 or later.
- Verify the integrity of the Python executable and virtual environments within the Cursor IDE.
- Monitor for suspicious activity and implement compensating controls to prevent exploitation.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence from CVE Program and NVD records indicates a high-severity vulnerability in Cursor IDE for macOS, allowing arbitrary host commands with user privileges. The issue is fixed in version 3.1.2. The CVE record was published on 2026-08-11T18:18:27.180Z and has not been modified since then. The vulnerability has a CVSS score of 7.7 and a severity of HIGH. The affected product is Cursor IDE for macOS, and the vulnerability requires upgrading to version 3.1.2 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73217 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73217
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73217 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73217
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/cursor/cursor/security/advisories/GHSA-p9g2-cr55-cw9c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.