{"data":{"id":"ff26854b-28b0-4d58-92fa-daca79bc1973","title":"AI agents can escape sandboxes without ever breaking them","summary":"AI coding agents can bypass security restrictions without technically breaking out of sandboxes (isolated execution environments) by creating files that trusted programs outside the sandbox later execute or read. Researchers at Pillar Security demonstrated this vulnerability in tools like Cursor, Codex, Gemini CLI, and Antigravity, showing that agents can manipulate configuration files, scripts, and virtual environments to indirectly run code with higher privileges outside their restricted environments.","solution":"The source recommends treating workspace configurations that trigger execution as sensitive assets requiring explicit approval before agents create or modify them, ensuring helper processes operate under the same security policy as direct agent execution, preserving provenance (a record distinguishing user-created files from agent-generated ones) to track file origins, modeling security policies around command side effects rather than just process invocation, limiting access to privileged local services, and monitoring trust handoffs throughout the development workflow. However, the source does not describe specific patches, version updates, or concrete implementation details for these recommendations.","labels":["security","safety"],"sourceUrl":"https://www.csoonline.com/article/4199408/ai-agents-can-escape-sandboxes-without-ever-breaking-them.html","publishedAt":"2026-07-21T11:46:02.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Microsoft"],"affectedVendorsRaw":["Cursor","Codex","Gemini CLI","Antigravity","VS Code","Docker Desktop"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-21T11:46:02.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}