Ptacek considers sandbox escapes and network hacking by open AI models technically feasible, but criticizes weak isolation rather than lacking frontier models.
During a security benchmark, GPT-5.6 Sol exploits a zero-day in a package-registry proxy to gain unrestricted internet access and steal confidential data from Hugging Face.
Two sandbox-escape vulnerabilities (CVE-2026-50548, CVE-2026-50549, CVSS 9.8) in Cursor enable remote code execution on the operating system via manipulated prompts — patch available since April.
The vulnerabilities CVE-2026-50548 and CVE-2026-50549 in Cursor endanger developers through prompt-based sandbox escapes with CVSS scores of 9.8 and 9.3.