Sandbox Escapes Discovered in Major AI Coding Tools

Sandbox Escapes Discovered in Major AI Coding Tools

First seen 20 Jul 2026, 23:09 UTC BleepingcomputerFeeds.4SysopsAiweekly.Cowww.pillar.securityCsoonline 84% similarity 65.2

Article Content

Browse articles
ThreatCluster

Pillar Security has identified vulnerabilities in four AI coding agents—Cursor, Codex, Gemini CLI, and Antigravity—that allow for sandbox escapes without direct attacks on the sandbox itself. These vulnerabilities stem from the agents writing files that trusted external tools later execute, effectively bypassing security boundaries. The attack methods exploit insufficient input validation and trust relationships between the agents and host systems. Notable CVEs include CVE-2026-48124 for Cursor and multiple issues in Antigravity. The findings highlight a systemic risk in agentic development environments, necessitating a reevaluation of security models. While some vulnerabilities have been patched, concerns remain about the potential for exploitation. Organizations using these tools are urged to reassess their security postures.

Key Points: • Four AI coding agents are affected: Cursor, Codex, Gemini CLI, and Antigravity. • Vulnerabilities allow sandbox escapes by writing files executed by trusted external tools. • Pillar Security identified multiple failure modes and has released detailed findings.

ThreatCluster AI

Timeline

2026-01-14
CVE-2026-22708 published
Codex CLI's vulnerability involves a command allowlist that does not enforce read-only operations.
BleepingComputer
2026-06-15
CVE-2026-48124 published
Cursor's vulnerability allows unsandboxed command execution through workspace-controlled configurations.
BleepingComputer
2026-07-21
Pillar Security publishes findings
Pillar Security releases a series of reports detailing sandbox escapes across major AI coding tools.
Pillar Security
Recent
Vulnerabilities acknowledged by vendors
Google classified two Antigravity findings as 'Other valid security vulnerabilities' but rated them difficult to exploit.
BleepingComputer

Community

Browse all →