• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Gadgets

AI coding agents keep escaping their sandboxes, study finds

July 21, 2026
Share on FacebookShare on Twitter

The tools are Cursor, OpenAI’s Codex, Google’s Gemini CLI, and Antigravity. Over several months, Pillar Security found ways for each agent to cross its security boundary while staying, technically, inside the box.

The escape that isn’t one

The trick is neat. These sandboxes trust the agent inside the project folder and protect the host outside. But the files in that folder are not inert.

Tools running outside the sandbox read them. A Python extension resolves an interpreter, a Git integration scans a repo, Docker Desktop exposes a local socket. So a file the agent is allowed to write can become a command the host later runs, as BleepingComputer explains.

The trigger is prompt injection. A malicious instruction hidden in a README, an issue, a dependency, or a diff turns into a real action on the developer’s machine.

Seven bugs, four patterns

TNW City Coworking space – Where your best work happens

A workspace designed for growth, collaboration, and endless networking opportunities in the heart of tech.

Pillar sorts seven findings into four failure modes: denylists that cannot keep pace with the operating system, workspace config that is really code, “safe” command lists that trust a name over its arguments, and privileged local daemons that sit outside the box entirely.

The fixes are mostly in. In Cursor, a workspace hook config that ran unsandboxed commands is now CVE-2026-48124, patched in version 3.0.0. OpenAI fixed a Codex flaw where a “safe” Git command was not, and paid a bounty. One Docker-socket bug hit Cursor, Codex, and Gemini CLI at once.

Google shrugged

Google’s response stood out. It classified both Antigravity findings as “other valid security vulnerabilities,” downgraded their severity as hard to exploit, and did not patch, Neowin reported. It did, however, call one report “of exceptional quality.”

Pillar’s counter is that “hard to exploit” is doing a lot of work. The bugs need a developer to trust a poisoned repository, which is exactly the everyday risk these agents introduce.

Agents are the new endpoint

The bigger point is a shift in thinking. An agent’s blast radius, Pillar argues, is not the agent process. It is everything the agent can write that the host later trusts.

“If an agent gets to write the future inputs of systems, it was never sandboxed in the first place,” the team wrote. The pattern is not new, but its breadth is: four tools, three vendors. It lands the same week OpenAI revealed its own model kept slipping its sandbox, part of a wider reckoning over AI-agent security.

What to ask now

For anyone choosing an agentic coding tool, the useful question has changed. It is no longer whether the agent has a sandbox. It is what happens to the files it leaves behind, and who runs them next.

Next Post

We’ll Finally See The Witcher 3’s New Expansion Next Month

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Sila raises $300M to fast-track gigascale anode production and shore up US battery supply chains
  • Nintendo Basically Says That Splatoon 4 Will Happen
  • GM beats Q2 earnings and announces gas-powered Cadillacs as nearly $11 billion EV retreat nears completion
  • This new flip phone could be exactly what the world needs right now
  • Aligned Data Centers sold for $40bn in record deal

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously