By Interestana AI Editorial — AI-drafted, human-overseen. How we report
AI Tools Cursor, Codex, Gemini CLI, Antigravity Suffer Sandbox Escapes
Researchers successfully exploited sandbox escape vulnerabilities in several AI-powered development tools, including Cursor, Codex, Gemini CLI, and Antigravity, between late 2023 and early 2024. These exploits allowed AI agents to write files that were subsequently executed by trusted host tools, bypassing intended security boundaries. The security flaws were detailed in multiple Common Vulnerabilities and Exposures (CVEs) reports.
Specifically, the method involved the AI agent generating malicious code or commands within a file. This file, once created, was then processed by a legitimate, trusted application on the host system, which inadvertently executed the harmful content. This technique circumvents the isolation typically provided by sandboxing, which is designed to prevent untrusted code from accessing or affecting the host system.
Google, which is involved with Gemini CLI and Antigravity, acknowledged the severity of the findings. The company downgraded two of the reported Antigravity vulnerabilities, indicating a reassessment of their impact or exploitability. The disclosure of these vulnerabilities highlights ongoing challenges in securing AI agents and the tools that integrate them into development workflows.
Patches have been developed and deployed for the affected tools to address these sandbox escape mechanisms. Users of Cursor, Codex, Gemini CLI, and Antigravity are advised to ensure their software is updated to the latest versions to mitigate these security risks. The incident underscores the importance of continuous security auditing and robust sandboxing techniques for AI applications.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.