Top AI coding agents can be easy victims to sandbox escapes, showing they aren’t as secure as they claim to be



  • Pillar researchers demonstrated sandbox escapes in AI coding agents
  • Exploits let attacker‑written configs run with trusted host privileges
  • Agentic security needs its own threat model, researchers claim

AI coding agents can be tricked into turning on their operators and assisting attackers in compromising the underlying systems, experts have warned.

Cybersecurity researchers Pillar have examined different methods of achieving the same results, finding that over the course of a couple of months, Cursor, Codex, Gemini CLI, and Antigravity were all able to reproduce sandbox escapes and boundary bypasses.

https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-2000-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img