💻
AI coding agents vulnerable to sandbox escapes, Pillar research finds
💻 Technology

AI coding agents vulnerable to sandbox escapes, Pillar research finds

Cybersecurity firm Pillar demonstrated sandbox escapes and boundary bypasses in four AI coding agents: Cursor, Codex, Gemini CLI, and Antigravity. An attacker can embed malicious instructions in a repository file such as a README, tricking the agent into modifying config files and running code with trusted host-level privileges. Researchers argue that agentic AI systems need a dedicated security threat model of their own.

Comments

No comments yet