As cited
Copy frozen at (site build).
vulnerabilities
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers demonstrated sandbox escape vulnerabilities in four AI coding tools: Cursor, Codex, Gemini CLI, and Antigravity. The attacks exploited a common pattern where AI agents write files that host tools subsequently execute, bypassing isolation mechanisms. Google patched Antigravity vulnerabilities and downgraded the severity of two findings.
Why it matters: Developers using these AI coding assistants face potential code execution risks if untrusted or compromised AI outputs are run without validation; patching and validating AI-generated code is critical.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers identified sandbox escape vulnerabilities in Cursor, Codex, Gemini CLI, and Antigravity by exploiting a pattern where artificial intelligence (AI) agents write files that host tools subsequently execute. Multiple CVEs were assigned, patches released, and Google downgraded the severity of two Antigravity findings. The attacks leverage trust relationships between the AI environment and underlying system tools.
Why it matters: Developers using these AI coding assistants face remote code execution risks if they trust AI-generated files without validation; security teams should patch immediately and review file handling in AI-assisted workflows.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers identified sandbox escape vulnerabilities in Cursor, Codex, Gemini CLI, and Antigravity by exploiting a pattern where artificial intelligence (AI) agents write files that host tools subsequently execute. Multiple CVEs were assigned, patches released, and Google downgraded the severity of two Antigravity findings. The attacks leverage trust relationships between the AI environment and underlying system tools.
Why it matters: Developers using these AI coding assistants face remote code execution risks if they trust AI-generated files without validation; security teams should patch immediately and review file handling in AI-assisted workflows.
- Source published
- First seen by Cybersecurity Tracker