Pillar Security researchers Eilon Cohen, Dan Lisichkin, and Ariel Fogel disclosed multiple sandbox escapes and boundary bypasses across Cursor, OpenAI’s Codex, Google’s Gemini CLI, and Antigravity. In most cases, the agents remained inside their sandboxes but wrote files or configurations that trusted host components later executed or interpreted with host privileges; another finding involved access to a privileged Docker daemon outside the sandbox boundary. Cursor and OpenAI patched identified vulnerabilities. According to Pillar Security, Google classified the two Antigravity findings as “Other valid security vulnerabilities” and downgraded their severity, while the researchers argued that agentic development requires a broader endpoint threat model.
Aug 7, 2026 · 6 sources
Aug 9, 2026 · 2 sources
Aug 6, 2026 · 4 sources
Aug 10, 2026 · 3 sources
Story comments
Loading comments…