HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Sandbox Escapes Discovered in Popular AI Coding Agents (Cursor, Codex, Gemini CLI, Antigravity)

Security researchers demonstrated sandbox‑escape techniques in four AI coding assistants, allowing them to execute code on the host machine. The findings underscore the need for robust control mapping and continuous audit evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Sandbox Escapes Discovered in Popular AI Coding Agents (Cursor, Codex, Gemini CLI, Antigravity)

What Happened — Researchers from Pillar Security demonstrated that four widely‑used AI‑driven coding assistants can break out of their intended sandboxes without directly attacking the sandbox itself. By writing files that trusted host tools later execute, the agents trigger command execution on the developer’s machine.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a control‑mapping gap: “sandbox‑only” policies are ineffective when downstream tools automatically act on generated artifacts.
  • Highlights the need for continuous evidence that file‑handling and command‑allowlist controls are enforced end‑to‑end, a core SOC 2 requirement for System Operations and Change Management.
  • Provides a real‑world example where a vendor‑issued CVE (e.g., CVE‑2026‑48124 for Cursor) must be tracked, remediated, and documented as part of a formal Vulnerability Management program.

Who Is Affected – Developers and organizations that rely on AI coding assistants in IDEs or CI pipelines, spanning SaaS, cloud‑native development platforms, and enterprise software shops.

Recommended Actions

  • Map each sandbox‑escape finding to the relevant SOC 2 control (e.g., CC6.1 – Logical Access, CC7.1 – Change Management).
  • Capture remediation tickets, patch versions, and verification logs as continuous audit evidence.
  • Review and tighten “trusted‑tool” allowlists, ensuring arguments are validated, not just command names.
  • Integrate automated scanning for malicious README/issue content that could serve as prompt‑injection vectors.

Technical Notes – The escapes exploit four failure modes: outdated denylist sandboxes, executable workspace configs, permissive command allowlists, and privileged local daemons (e.g., Docker socket). Reported CVEs include CVE‑2026‑48124 (Cursor) and pending CVEs for other agents. Vendors have released patches (Cursor v3.0.0, Codex v0.95.0, Gemini CLI updates). Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →