Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Security researchers have identified sandbox escape vulnerabilities affecting multiple AI coding assistants, including Cursor, Codex, Gemini CLI, and Antigravity. The flaws enable attackers to break out of the sandboxed environments these tools use to execute untrusted code, potentially allowing unauthorized access to the host system or sensitive data. The vulnerabilities were disclosed in a coordinated manner, with the affected vendors notified prior to publication. The exact impact varies by tool, but the common risk is that a malicious prompt or code snippet could trigger an escape, leading to arbitrary code execution outside the sandbox. Users are advised to apply available patches and exercise caution when processing untrusted inputs.
Sandbox escapes in AI coding tools could let attackers execute arbitrary code on developers' machines.