The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at Pillar Security disclosed sandbox escape vulnerabilities in four AI coding agents: Cursor, OpenAI Codex, Google Gemini CLI, and Antigravity.
- Instead of attacking sandboxes directly, they used prompt injections planted in files like READMEs or issues, causing agents to write files that trusted local tools later executed outside the sandbox.
- Most issues are patched, including Cursor fixes in version 3.0.0 and an OpenAI patch in Codex CLI v0.95.0, though Google downgraded its two Antigravity findings as hard to exploit.
- The findings matter because they show a shared failure across vendors, meaning a sandbox alone does not guarantee safety when files an agent writes are acted on by host tools.
What to watch next
- CVEs still pending for several Cursor and Codex CLI findings and how they are finally scored
- Whether Google revisits its downgrade of the Antigravity vulnerabilities amid researcher disagreement
- Whether vendors adopt Pillar's approach of monitoring when trusted tools execute agent-written files
Coverage1
1 report
International1
All filed from United States
Named United States · Israel · Antigravity · Codex · Cursor · Gemini CLI · Google · OpenAI · Ariel Fogel · Cymulate · Dan Lisichkin · Eilon Cohen · Pillar Security
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
