Researchers discovered sandbox escape vulnerabilities in four AI coding tools by exploiting a common attack vector: convincing AI agents to write files that trusted host tools later execute.
Security researchers have identified sandbox escape vulnerabilities affecting Cursor, Codex, Gemini CLI, and Antigravity. The exploits share a similar mechanism—attackers manipulate AI agents into writing files that host tools subsequently run with elevated privileges, bypassing sandbox restrictions.
The attack chain works by having the AI write malicious code to disk, which is later executed by trusted processes on the host system. This effectively bridges the gap between the sandboxed AI environment and the underlying system, granting attackers access beyond intended boundaries.
Multiple CVEs have been assigned to these vulnerabilities. Patch releases are now available for affected tools. Google, which maintains Gemini CLI, has already released fixes addressing the issue.
For Antigravity, Google took the additional step of downgrading two of the reported findings, suggesting the researchers may have overestimated the severity or scope of those particular vulnerabilities. The company did acknowledge and address other reported issues.
The discovery highlights a growing concern in AI security: the difficulty in truly isolating AI agents from system resources. Even well-designed sandboxes can be compromised when AI systems have legitimate reasons to interact with file systems and tools.
This pattern of vulnerability—where AI tools are tricked into writing executables or scripts—is likely to become increasingly relevant as more developers integrate AI agents into their workflows. The findings underscore the need for careful security considerations when granting AI systems file write access, even in restricted environments.
Developers using these tools should update to patched versions immediately. Security researchers recommend implementing additional access controls and monitoring file creation and execution patterns from AI processes.
Hackers are actively exploiting vulnerable WordPress installations to compromise websites, according to multiple cybersecurity firms. WordPress released patches for two critical security flaws last week.
Congress must reauthorize Section 702 of the Foreign Intelligence Surveillance Act by June 12, but lawmakers remain deadlocked on reforms. The temporary 45-day extension granted in late April expires next week with no deal in sight.
The JadePuffer autonomous AI agent has evolved to target machine learning infrastructure, deploying custom malware called EncForge that encrypts training datasets, vector databases, and model checkpoints.
Taiwan's prosecutors have indicted a former TSMC deputy manager for allegedly stealing semiconductor trade secrets. Authorities mark this as the first National Security Act case involving China.