logo

Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution

ID: 9572358a-8999-5948-85b4-e0c3667116c6

STIX ID: report--9572358a-8999-5948-85b4-e0c3667116c6

Feed Name: CyberScoop

Threat Score
72/100

Date Published: 2026-04-20

Date Updated: 2026-04-21

Author: djohnson

...
...

Researchers at Pillar Security disclosed a prompt-injection vulnerability in Google's Antigravity AI developer tool where a native file-search utility ('find_by_name') could be invoked before Secure Mode protections, enabling arbitrary remote code execution; the issue was reported on Jan 6, patched on Feb 28 with a bug bounty awarded, and the report warns that similar unvalidated-input prompt-injection risks exist across other agentic coding AI systems and that sanitization-only controls are insufficient.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.