Top AI coding agents can be easy victims to sandbox escapes, showing they aren't as secure as they claim to be
- Pillar researchers demonstrated sandbox escapes in AI coding agents
- Exploits let attacker‑written configs run with trusted host privileges
- Agentic security needs its own threat model, researchers claim
AI coding agents can be tricked into turning on their operators and assisting attackers in compromising the underlying systems, experts have warned.
Cybersecurity researchers Pillar have examined different methods of achieving the same results, finding that over the course of a couple of months, Cursor, Codex, Gemini CLI, and Antigravity were all able to reproduce sandbox escapes and boundary bypasses.
In theory, a threat actor could create a repository containing malicious content (for example, a README file, a dependency, or similar) and trick the developer into using it. The malicious instructions tell the agent to create or modify a project configuration file, but since everything happens inside the workspace, no alarms are triggered.
Fixing the problems
Then, a host component outside the sandbox...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE