ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Vulnerabilities

Sandbox escapes in Cursor, Codex, Gemini CLI, and Antigravity

Source headline: Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 11 hours ago

Intelligence Summary

Researchers demonstrated sandbox escapes in multiple AI coding assistants. The key technique involves tricking the agent into writing files that later run on trusted host tools. Affected products include Cursor, GitHub Copilot Codex, and Google’s Gemini CLI. Antigravity findings were partially downgraded by Google after review. The issue highlights that AI tools with host access can be bypassed if file execution paths are not tightly controlled.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#ai-agents #developer-tools #sandbox-escape #host-execution #prompt-driven-file-writes
Original reporting BleepingComputer Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Open original source