PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73217 cursor CVE debrief

CVE-2026-73217 debrief based on CVE Program and NVD records. The vulnerability affects Cursor IDE for macOS, allowing an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper, enabling arbitrary host commands with user privileges. This issue is fixed in version 3.1.2. Developers and security teams should assess exposure and take action to prevent exploitation, including verifying the integrity of the Python executable and virtual environments within the Cursor IDE.

Vendor
cursor
Product
Unknown
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Developers and security teams using Cursor IDE for macOS should assess exposure and take action to prevent exploitation. This includes verifying the integrity of the Python executable and virtual environments within the Cursor IDE, monitoring for suspicious activity, and implementing compensating controls to prevent exploitation. The vulnerability has a high CVSS score and severity, and affected product deployments should be identified and remediated as a

Why it matters

CVE-2026-73217 is a high-severity vulnerability in Cursor IDE for macOS, allowing arbitrary host commands with user privileges. Developers and security teams should assess exposure and upgrade to version 3.1.2 or later.

  • Potential for arbitrary host commands with user privileges, allowing modifying files outside the workspace and launching applications
  • Need for verification of Cursor IDE version and virtual environment integrity
  • Potential for exploitation requires upgrading to version 3.1.2 or later

Technical summary

CVE-2026-73217 is a high-severity vulnerability in Cursor IDE for macOS, allowing an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper, enabling arbitrary host commands with user privileges. The issue is fixed in version 3.1.2. The vulnerability has a CVSS score of 7.7 and a severity of HIGH. The affected product is Cursor IDE for macOS, and the vulnerability requires upgrading to version 3.1.2 or later. The vulnerability allows arbitrary host commands with user privileges, including modifying files outside the workspace and launching applications.

Defensive priority

High priority for developers and security teams using Cursor IDE

Recommended defensive actions

  • Developers and security teams should assess exposure and upgrade to Cursor IDE version 3.1.2 or later.
  • Verify the integrity of the Python executable and virtual environments within the Cursor IDE.
  • Monitor for suspicious activity and implement compensating controls to prevent exploitation.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from CVE Program and NVD records indicates a high-severity vulnerability in Cursor IDE for macOS, allowing arbitrary host commands with user privileges. The issue is fixed in version 3.1.2. The CVE record was published on 2026-08-11T18:18:27.180Z and has not been modified since then. The vulnerability has a CVSS score of 7.7 and a severity of HIGH. The affected product is Cursor IDE for macOS, and the vulnerability requires upgrading to version 3.1.2 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73217 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73217

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73217 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73217

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.