Skip to content

164news.com

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Researchers escaped four top AI coding agents’ sandboxes without ever breaking them

Posted on July 21, 2026 By 164news66 No Comments on Researchers escaped four top AI coding agents’ sandboxes without ever breaking them

AI Coding Agents Escaping Sandboxes: A Study Finds

Researchers Escape Four Top AI Coding Agents’ Sandboxes Without Breaking Them

Security researchers successfully navigated the sandboxes of four prominent AI coding tools—Cursor, OpenAI’s Codex, Google’s Gemini CLI, and Antigravity—without compromising their integrity. Notably, the agents remained within the sandbox environment while executing actions that led to escaping. Three vendors have already patched the vulnerabilities. Google, however, downgraded the severity of the issues and chose not to patch them, despite acknowledging one report as "of exceptional quality."

The Escape Mechanism

The researchers utilized prompt injection techniques to exploit these sandboxes. By injecting malicious instructions into seemingly harmless files within the sandboxed environment, they were able to execute commands on their host systems. This happens because tools outside the sandbox trust and read the files generated by the agents inside. Extensions, Git integrations, and Docker Desktop are examples of how a file written by an agent can become a command executed later.

The Vulnerabilities

Pillar Security identified seven distinct vulnerabilities categorized into four main failure patterns:

  1. Denylists That Cannot Keep Pace: These fail to restrict access to system commands.
  2. Workspace Config as Code: Sensitive configurations are treated as code, accessible to malicious actors.
  3. "Safe" Command Lists Trusting Name Over Arguments: This allows for command injection vulnerabilities.
  4. Privileged Local Daemons Outside the Box: These run with elevated privileges and can be exploited.

Fixes and Response from Vendors

The majority of the identified issues have been patched. Cursor addressed a critical vulnerability (CVE-2026-48124) in version 3.0.0. OpenAI fixed a Codex flaw, and one Docker-socket bug affected all three tools: Cursor, Codex, and Gemini CLI.

Google’s response stood out, classifying the Antigravity findings as "other valid security vulnerabilities" and downgrading their exploitability. Despite this, they acknowledged one report as exceptional. Pillar counters that even if these bugs are less exploitable, they introduce a daily risk to developers who trust poisoned repositories.

A Shifting Perspective on AI Agent Security

The key takeaway is a shift in perspective regarding AI agent security. The potential blast radius of an agent extends beyond its process; it encompasses everything the agent can write that might later be trusted and executed by host systems. This means the question for users considering AI coding tools is no longer about whether the agent has a sandbox but what happens to the files it generates and who runs them afterward.

Clock

Post navigation

Previous Post: Nvidia says Vera Rubin is in full production, with OpenAI set to deploy at scale in Q3
Next Post: Apple is launching a Klarna-backed device leasing program called Apple Upgrade on July 28

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Editor's Picks

  • Water Filter Installation Denver
  • Denver Plumbing for Renters
  • Plumber for Restaurant Installations Denver
  • 24/7 Plumber Available in Denver
  • Denver Water Softener Installation
  • Clock
  • Thyroid Test
  • sailboat
  • Steam Boat
  • Submarine

Recent Posts

  • The US is clearing the runway for air taxis and supersonic jets
  • US and China reportedly plan a fresh round of AI talks in September
  • Brazil’s Pix becomes a trade flashpoint with the US, and the world is watching
  • Kanishka Narayan becomes the UK’s first cabinet-level AI minister
  • Pan Am Clipper Endeavor Is Found After Over 70 Years Lost at Sea

Recent Comments

  1. houseofluckcasino on Mick Jagger says AI is fine for musicians, as long as it does not sound like him
  2. happybingo on Mick Jagger says AI is fine for musicians, as long as it does not sound like him
  3. codwin on Mick Jagger says AI is fine for musicians, as long as it does not sound like him
  4. c444gameapk on Google DeepMind launched an AI biosecurity programme to fight biological threats
  5. bunny casino on Google DeepMind launched an AI biosecurity programme to fight biological threats

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026

Editor's Picks

  • Water Filter Installation Denver
  • Denver Plumbing for Renters
  • Plumber for Restaurant Installations Denver
  • 24/7 Plumber Available in Denver
  • Denver Water Softener Installation
  • Clock
  • Thyroid Test
  • sailboat
  • Steam Boat
  • Submarine

Copyright © 2026 164news.com.

Powered by PressBook Dark WordPress theme