Our research team found a disk isolation bug in Cloudflare Containers that let a sandbox read other customers’ files: directory listings, SQLite databases, Chromium profiles, .env files, and credential files.
Cloudflare Sandboxes and Browser Run use the same disk implementation and were affected too. We reported it to Cloudflare on September 4, 2026, and they fixed it shortly after.
We worked with Cloudflare on a joint write-up of the vulnerability, the root cause, and the fix. Read the full technical breakdown on the Cloudflare blog.
This is the sixth sandbox escape our team has published since July 2026, after SharedRoot (Claude Cowork), Beltdown (Claude Code), Beltdown2 (Cursor CLI), Docker’s VMM, and OpenAI Codex’s sandbox.
Guest to host: escaping Docker's hypervisor
Sep 19, 2026 • 5 min read
Escaping the OpenAI Codex sandbox, twice
Sep 15, 2026 • 5 min read
Beltdown2: Escaping the Cursor CLI sandbox
Sep 12, 2026 • 7 min read
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
