Pillar Security Discovers Sandbox Escape Vulnerabilities in Major AI Coding Agents
Security researchers at Pillar Security disclosed multiple sandbox escapes and boundary bypasses across Cursor, OpenAI Codex, Google Gemini CLI, and Antigravity. In most cases, the agents remained inside their sandboxes but wrote files that trusted host components later executed, loaded, or scanned; other findings involved denylist weaknesses and access to privileged local daemons outside the sandbox boundary.