PatchSiren

cursor CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cursor CVE published 2026-08-11

CVE-2026-73218

CVE-2026-73218 is a high-severity vulnerability in Cursor IDE for macOS, allowing an agent in Auto-Run Sandbox mode to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges. This issue is fixed in version 3.0.0. The vulnerability impacts macOS systems with Cursor IDE installed, [truncated]

HIGH cursor CVE published 2026-08-11

CVE-2026-73217

CVE-2026-73217 debrief based on CVE Program and NVD records. The vulnerability affects Cursor IDE for macOS, allowing an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper, enabling arbitrary host commands with user privileges. This issue is fixed in version 3.1.2. Developers and security teams should assess exposure and take action to prev [truncated]

HIGH cursor CVE published 2026-07-15

CVE-2026-61613

CVE-2026-61613 is a high-severity vulnerability in Cursor Cloud Agent that allows code execution. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, [truncated]

HIGH cursor CVE published 2026-06-15

CVE-2026-48124

CVE-2026-48124 is a high-severity vulnerability (CVSS Score: 8.5) affecting Cursor, a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from `.claude/settings.local.json` without dedicated user approval. A malicious workspace or agent-created file could configure hooks that run local commands in the user's context [truncated]