Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Pillar Security Discovers Sandbox Escape Vulnerabilities in Major AI Coding Agents
00

Pillar Security Discovers Sandbox Escape Vulnerabilities in Major AI Coding Agents

Jul 21, 2026

Pillar Security researchers Eilon Cohen, Dan Lisichkin, and Ariel Fogel disclosed multiple sandbox escapes and boundary bypasses across Cursor, OpenAI’s Codex, Google’s Gemini CLI, and Antigravity. In most cases, the agents remained inside their sandboxes but wrote files or configurations that trusted host components later executed or interpreted with host privileges; another finding involved access to a privileged Docker daemon outside the sandbox boundary. Cursor and OpenAI patched identified vulnerabilities. According to Pillar Security, Google classified the two Antigravity findings as “Other valid security vulnerabilities” and downgraded their severity, while the researchers argued that agentic development requires a broader endpoint threat model.

AI coding agent sandbox escapes

  • ▪Pillar Security researchers Eilon Cohen, Dan Lisichkin, and Ariel Fogel discovered and reproduced sandbox escapes across Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity.
  • ▪In most of the findings, an AI agent wrote a file inside its workspace that a trusted tool outside the sandbox later ran, loaded, scanned, or treated as safe.

Workspace configuration execution risks

  • ▪Cursor patched a workspace-controlled .claude hook configuration vulnerability tracked as CVE-2026-48124 in version 3.0.0.
  • ▪A Cursor vulnerability allowed an AI agent to edit a virtualenv interpreter that the editor's Python extension subsequently executed during discovery.
  • ▪A Cursor vulnerability involving Git metadata redirection via fsmonitor was patched in version 3.0.0, with a CVE pending.

Host trust boundary failures

  • ▪OpenAI patched a Codex CLI command allowlist vulnerability in version 0.95.0, which trusted git show by name while the actual invocation was not read-only.
  • ▪According to Pillar Security, Google classified two Antigravity findings—a macOS Seatbelt denylist bypass and a .vscode task-configuration bypass—as "Other valid security vulnerabilities" and downgraded their severity.

Privileged daemon exposure

  • ▪A Docker socket vulnerability affecting Codex, Cursor, and Gemini CLI allowed sandboxed agents to reach a privileged local daemon to run unsandboxed code.
  • ▪Pillar Security recommends that organizations restrict agent access to privileged local services and monitor trust handoffs throughout the development workflow.

Agentic endpoint threat modeling

  • ▪Pillar Security recommends treating workspace configurations that can trigger execution as sensitive assets and requiring explicit approval before agents modify host-side automation.
  • ▪Pillar Security argues that an AI agent's blast radius is not the agent process itself, but includes everything the agent can write that the host later trusts.

6 sources

Pillar
The Week of Sandbox Escapes
View source article
Windowsnews
AI Coding Tools' Sandbox Flaw Lets Attackers Execute Code via Trusted Host Apps
View source article
Csoonline
AI agents can escape sandboxes without ever breaking them
View source article
Thenextweb
AI coding agents keep escaping their sandboxes, study finds
View source article
Bleepingcomputer
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
View source article

Featured stories

View more in AI coding assistants

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI and Synopsys partner to develop AI model for chip design

Sep 30, 2026 · 3 sources

OpenAI unveils ChatGPT overhaul with shared workspaces, plugin system, and $500 monthly tier at DevDay

Sep 29, 2026 · 13 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

Story comments

Loading comments…

Related Projects

OpenAIGoogleCursor

Topics

AI coding assistantsAI for developersAI security

Featured stories

View more in AI coding assistants

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI and Synopsys partner to develop AI model for chip design

Sep 30, 2026 · 3 sources

OpenAI unveils ChatGPT overhaul with shared workspaces, plugin system, and $500 monthly tier at DevDay

Sep 29, 2026 · 13 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources