Bottom Line: Sandbox escapes in AI agents enable attackers to execute code on the host system through files written by the AI after breaking out of the sandbox.
Security researchers have demonstrated sandbox breakouts in multiple AI agents and developer IDEs by prompting the AI model to write files that are subsequently executed by trusted host tools. Multiple CVEs have been registered, patches distributed, and Google has downgraded two findings related to the Antigravity platform.
Researchers have shown that multiple AI-powered developer tools – including Cursor, OpenAI Codex, Google Gemini CLI, and Antigravity – are vulnerable to sandbox escape attacks. The attack vector exploits a central weakness: AI agents running in isolated sandboxes write files to the host system, which are then executed by local tools that treat these files as trustworthy.
The security risk arises from the architecture of these systems: the AI agent is given the ability to generate and store code or configuration files. When downstream processes automatically execute these files – such as when launching build tools, virtualization software, or script interpreters – an attacker can use targeted prompts to manipulate the AI into injecting malicious content. The sandbox is thereby circumvented since execution occurs outside its control.
Multiple CVEs have been registered for remediation and patches are already available or in progress. Google has additionally downgraded two findings submitted against Antigravity, possibly due to mitigations or different risk assessment. For CISOs, this means that AI-based developer tools in the infrastructure must be critically reviewed – particularly where they access local file systems and execution environments.
Source: www.bleepingcomputer.com · Published July 20, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.