Skip to content
Escaping The Cloudflare Sandbox

Escaping The Cloudflare Sandbox

accomplish.ai • September 25, 2026

Our research team found a disk isolation bug in Cloudflare Containers that let a sandbox read other customers’ files: directory listings, SQLite databases, Chromium profiles, .env files, and credential files.

Cloudflare Sandboxes and Browser Run use the same disk implementation and were affected too. We reported it to Cloudflare on September 4, 2026, and they fixed it shortly after.

We worked with Cloudflare on a joint write-up of the vulnerability, the root cause, and the fix. Read the full technical breakdown on the Cloudflare blog.

This is the sixth sandbox escape our team has published since July 2026, after SharedRoot (Claude Cowork), Beltdown (Claude Code), Beltdown2 (Cursor CLI), Docker’s VMM, and OpenAI Codex’s sandbox.

Guest to host: escaping Docker's hypervisor

Sep 19, 2026 • 5 min read

Escaping the OpenAI Codex sandbox, twice

Sep 15, 2026 • 5 min read

Beltdown2: Escaping the Cursor CLI sandbox

Sep 12, 2026 • 7 min read