Impact
A malicious agent in Cursor’s Auto‑Run Sandbox mode can replace a virtual environment’s Python executable with a wrapper that the Microsoft Python extension runs outside the sandbox. When executed, this wrapper performs arbitrary host commands with the user’s privileges, allowing the attacker to modify files beyond the workspace and launch applications. This vulnerability satisfies CWE‑693, indicating that the system allows manipulation of process control values that should be protected.
Affected Systems
Cursor IDE for macOS, versions prior to 3.1.2 are affected. The CVE applies to any installation of the IDE that uses the Auto‑Run Sandbox mode and the Microsoft Python extension.
Risk and Exploitability
The CVSS score of 7.7 indicates a high impact if exploited. The EPSS score is below 1 %, suggesting that in the current environment exploit attempts are unlikely. The vulnerability is not listed in CISA’s KEV catalog. However, the exploit requires a malicious wrapper inside the sandbox, a condition that can be achieved by a local attacker or via compromised extensions. If the conditions are met, arbitrary host command execution is possible, granting the attacker full user‑level control over the system.
OpenCVE Enrichment