Feeds.4Sysops
Sandbox Escapes Discovered in Major AI Coding Tools
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Pillar Security has identified vulnerabilities in four AI coding agents—Cursor, Codex, Gemini CLI, and Antigravity—that allow for sandbox escapes without direct attacks on the sandbox itself. These vulnerabilities stem from the agents writing files that trusted external tools later execute, effectively bypassing security boundaries. The attack methods exploit insufficient input validation and trust relationships between the agents and host systems. Notable CVEs include CVE-2026-48124 for Cursor and multiple issues in Antigravity. The findings highlight a systemic risk in agentic development environments, necessitating a reevaluation of security models. While some vulnerabilities have been patched, concerns remain about the potential for exploitation. Organizations using these tools are urged to reassess their security postures.
Key Points: • Four AI coding agents are affected: Cursor, Codex, Gemini CLI, and Antigravity. • Vulnerabilities allow sandbox escapes by writing files executed by trusted external tools. • Pillar Security identified multiple failure modes and has released detailed findings.