logo

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

ID: 0775b923-4bbf-55b6-a6c5-9488361bf5d8

STIX ID: report--0775b923-4bbf-55b6-a6c5-9488361bf5d8

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Ax Sharma

...
...

Pillar Security researchers disclosed a class of "configuration-based sandbox escape" flaws across several AI coding agents (Cursor, Codex CLI, Gemini CLI, Antigravity) in which an agent, while remaining sandboxed, writes files that trusted local tools later execute—resulting in host code execution. Multiple issues were reproduced, tracked with CVEs (for example CVE-2026-48124) and mostly patched, though some vendors assessed certain findings as harder to exploit; the work exposes a systemic cross-vendor weakness in how local tooling trusts repository/workspace files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.