Sandbox Escapes Patched in Cursor, Codex, Gemini, and Antigravity
- Source
- BleepingComputer
- Time
- 11:44 PM
- Weight
- 94/100
Security researchers from Pillar Security have revealed a series of sandbox escape vulnerabilities affecting prominent AI-driven coding tools, including Cursor, OpenAI’s Codex, and Google’s Gemini CLI and Antigravity. Rather than attacking the sandbox environment directly, these exploits leverage a pattern where the AI agent writes files within a workspace that are subsequently executed or processed by trusted tools running on the host machine.
By using prompt injection through malicious files like READMEs or repositories, an attacker can trigger unauthorized command execution on a developer’s system. The identified flaws were categorized into several failure modes, such as the abuse of privileged local daemons and workspace configurations that function as executable code.