Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cursor: Sandbox escape via launching privileged containers
Vulnerability Description
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home directory and enabling host command execution with the user's privileges without an additional permission prompt. This issue is fixed in version 3.0.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
特权管理不恰当
Vulnerability Title
Cursor 权限许可和访问控制问题漏洞
Vulnerability Description
Cursor是Cursor组织的一款深度集成AI的智能代码编辑器。 Cursor 3.0.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于Auto-Run Sandbox模式下的权限管理不当,允许代理启动特权容器并挂载Docker的virtiofs0,导致攻击者可读写用户主目录并以用户权限执行主机命令。
CVSS Information
N/A
Vulnerability Type
N/A