bleeping-computer · Crawled Jul 20, 2026

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Read original article ↗

AI Summary

Security researchers from Pillar Security demonstrated sandbox escape techniques across four AI coding agents: Cursor, OpenAI's Codex CLI, Google's Gemini CLI, and Antigravity. The attacks leverage prompt injection to manipulate files within the sandboxed workspace, which are later executed or interpreted by trusted tools running outside the sandbox, leading to command execution on the host. These techniques exploit design flaws such as over-trusted configuration files, incomplete denylists, and privileged local daemons. Most vulnerabilities have been patched, though some CVEs are still pending.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.