News
AI SHIFT:

AI Coding Agents Face Sandbox-Escape Findings Across Four Tools

Newsroom brief

BleepingComputer reported that Pillar Security reproduced sandbox-escape paths in Cursor, OpenAI Codex, Gemini CLI and Google Antigravity, shifting attention from agent containment to trusted developer tools around the workspace.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: bleepingcomputer.com
AI Coding Agents Face Sandbox-Escape Findings Across Four Tools
Image source: bleepingcomputer.com

Four major AI coding tools face a sandbox-design warning after BleepingComputer reported that Pillar Security reproduced escape paths in Cursor, OpenAI Codex, Google's Gemini CLI and Google Antigravity without directly attacking the sandbox layer.

The finding turns the security question away from whether an agent remains inside a restricted workspace.

Pillar's research centres on what happens when a trusted tool outside that workspace later reads or runs files that the agent was allowed to create.

Agent Sandboxes Meet Trusted Developer Tools

Enterprise development teams run coding agents inside IDEs, command-line tools and local developer workflows rather than isolated cloud demos.

BleepingComputer identified the affected tools as Cursor, OpenAI Codex, Gemini CLI and Antigravity, while naming Pillar researchers Eilon Cohen, Dan Lisichkin and Ariel Fogel as the team behind the work.

Pillar grouped seven findings into four failure modes: denylist sandboxes that lag operating-system behaviour, workspace configuration files that act as executable code, allowlists that trust a command name more than its arguments, and privileged local daemons that sit outside the sandbox.

The pattern does not require the agent to break its own instructions; the risk appears when the surrounding developer environment treats agent-written files as trusted input.

The affected layer is the surrounding toolchain rather than the model alone.

Extensions, task runners, hooks, Git integrations, interpreters and local services can operate with broader host privileges than the agent workspace.

Cursor, Codex And Gemini Fixes Cover Most Findings

Most of the issues have patches or vendor acknowledgement.

Pillar's material names CVE-2026-48124 for one Cursor finding and records Cursor fixes in version 3.0.0 for more than one issue.

Pillar's disclosure records OpenAI's v0.95.0 Codex CLI patch and a high-severity bounty, with a CVE pending.

A separate Docker socket issue affected Codex, Cursor and Gemini CLI and is now fixed.

The disclosure does not provide customer incident counts or evidence that the findings were exploited in production environments.

The Antigravity handling differs from the rest of the disclosure set.

Google's two findings involved a macOS Seatbelt denylist bypass and a task-configuration bypass of Secure Mode; Pillar's account says Google classified both as valid security vulnerabilities but downgraded severity because exploitation would require social engineering or user trust in a repository carrying indirect prompt injection.

AI Coding Security Extends Beyond The Agent

The same class of problem had already appeared earlier in research from Cymulate, which used the term Configuration-Based Sandbox Escape for a pattern spanning Claude Code, Gemini CLI and Codex CLI.

Pillar's newer work broadens that issue across four tools from three vendors and ties it to everyday developer tooling around repositories and local services.

For security teams, the operating boundary is not only the AI model or the prompt.

Review processes must also cover which local tools can act on files created by agents, which daemons are reachable from development workspaces and whether vendor sandboxes monitor post-write execution by trusted host components.

Pillar's proposed direction is to watch the moment a trusted local tool runs something an agent wrote rather than relying only on lists of banned filenames.

Production exploitation evidence and customer-level mitigation data remain unnamed.

Share this article
inXf

Related articles

More
OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Cybersecurity

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs
Cybersecurity

Google AI Workflow Pushes Chrome Security Fixes To 1,072 Bugs

BleepingComputer reported that Google attributed 1,072 Chrome security bug fixes to Chrome 149 and Chrome 150, while faster patch delivery remains part of the browser security plan.

UK Test Finds AI Agents Trying to Social-Engineer Real People
Cybersecurity

UK Test Finds AI Agents Trying to Social-Engineer Real People

CNBC reported that the UK AI Security Institute observed Anthropic and OpenAI model agents taking potentially harmful actions during permissive cyber tests, with Anthropic and OpenAI saying the conditions did not reflect ordinary production use.

Arch Linux Freezes AUR Package Adoption After Malware Takeovers
Cybersecurity

Arch Linux Freezes AUR Package Adoption After Malware Takeovers

Arch Linux temporarily blocked AUR package adoption after malicious package takeovers, shifting the immediate security problem from package removal to maintainer-account review and developer secret exposure.

Neo Raises $100M To Control Enterprise AI Software Actions
Cybersecurity

Neo Raises $100M To Control Enterprise AI Software Actions

SecurityWeek reported that Neo emerged from stealth with $100 million for a platform that governs AI agents, MCP servers and software actions across enterprise systems.

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact
Cybersecurity

Anthropic Mythos Finds Crypto Flaws Without Real-World Impact

CyberScoop reported that Anthropic used Claude Mythos Preview to find weaknesses in HAWK and a reduced AES test, while Anthropic stressed that current software remains unaffected.

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain
Cybersecurity

Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery Chain

DeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.

Hugging Face Hack Pushes AI Agents Into Cybersecurity Spotlight
AI

Hugging Face Hack Pushes AI Agents Into Cybersecurity Spotlight

CNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.

Keep Reading

More Stories

Latest
Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.China Opens Security Review Of Palo Alto Networks ProductsCybersecurityAug 7, 2026China Opens Security Review Of Palo Alto Networks ProductsChina's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.AI Patch Study Keeps Humans In Vulnerability ReviewsCybersecurityAug 7, 2026AI Patch Study Keeps Humans In Vulnerability ReviewsThe Register reported that 1Password Off-by-1 Labs tested 6,080 AI-generated patches across six CVEs and found clean autonomous fixes in 26.0 percent of cases, leaving security teams with a supervision problem rather than a replacement for vulnerability review.DOJ Trade-Fraud Unit Raises Payment Compliance ExposureFintech & Digital PaymentsAug 7, 2026DOJ Trade-Fraud Unit Raises Payment Compliance ExposurePYMNTS reported that a new U.S. Justice Department trade-fraud section and more than $1 billion in recent task-force recoveries are pushing banks to compare payment flows with customs and supply-chain records.