Sandbox Escapes Affect Major AI Coding Tools

Sandbox Escapes Affect Major AI Coding Tools

First seen 20 Jul 2026, 23:09 UTC BleepingcomputerFeeds.4SysopsAiweekly.Cowww.pillar.security 83% similarity 57.8

Article Content

Browse articles
ThreatCluster

Pillar Research revealed vulnerabilities in four AI coding agents: Cursor, Codex, Gemini CLI, and Antigravity, allowing sandbox escapes without direct attacks. The agents can write files that trusted tools outside the sandbox execute, leading to potential unauthorized actions. The research, published as 'The Week of Sandbox Escapes,' identifies four failure modes and highlights that many vulnerabilities have been patched. Specific CVEs include CVE-2026-48124 for Cursor, which was fixed in version 3.0.0. Other issues affected Codex and Gemini CLI, with patches released by OpenAI and Google. The findings emphasize the need for better governance of AI coding tools as they become integral to development workflows.

Key Points: • Four AI coding agents are vulnerable to sandbox escapes via file writes. • Pillar Research identified four failure modes in their recent findings. • Several vulnerabilities have been patched, but risks remain due to agent behavior.

ThreatCluster AI

Timeline

2026-06-15
CVE-2026-48124 published
Cursor's vulnerability allowed unsandboxed command execution and was fixed in version 3.0.0.
Bleepingcomputer
2026-07-20
Pillar Research publishes sandbox escape findings
Research details vulnerabilities in Cursor, Codex, Gemini CLI, and Antigravity, highlighting escape methods.
Pillar Security
2026-07-20
OpenAI and Google release patches
OpenAI patched vulnerabilities in Codex CLI, while Google addressed issues in Antigravity, following Pillar's findings.
Bleepingcomputer

Community

Browse all →