Security researchers from Pillar Security demonstrated sandbox escapes in Cursor, OpenAI Codex CLI, Google Gemini CLI, and Antigravity by planting files that trusted tools outside the sandbox later executed or scanned. The findings showed multiple failure modes, including hook abuse, interpreter execution, Git metadata tricks, command allowlist bypasses, and Docker socket access, with several issues patched or acknowledged by vendors. #Cursor #OpenAICodex #GeminiCLI #Antigravity #PillarSecurity
Keypoints
- Pillar Security broke out of sandboxes in four AI coding agents.
- The escapes relied on files trusted by tools outside the sandbox.
- Prompt injection in workspace content was a key trigger.
- Cursor, Codex CLI, Gemini CLI, and Antigravity were all affected.
- Several flaws were patched, and Google downgraded two Antigravity reports.