Impact
Prior to version 3.0.0, the Cursor IDE on macOS could allow an agent running in Auto‑Run Sandbox mode to launch a privileged Docker container when Docker Desktop and the Dev Containers CLI were installed. By mounting Docker's virtiofs0, the agent could read and write files in the user's home directory and then execute commands on the host with the same privileges as the user. The vulnerability is a classic example of improper privilege management (CWE‑269).
Affected Systems
The affected product is Cursor IDE for macOS, produced by Cursor. Any version prior to 3.0.0 is vulnerable, regardless of minor sub‑releases. No specific build numbers are supplied; the advisory only states that the issue exists in all releases before 3.0.0.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the presence of Docker Desktop and the Dev Containers CLI and the activation of Cursor's Auto‑Run Sandbox mode, so the attack vector is local with privileged container launch. Remediation is straightforward: upgrade to 3.0.0 or later.
OpenCVE Enrichment