Top AI coding agents can be easy victims during sandbox escapes, showing that they are not as secure as they claim to be.


  • Pillar researchers demonstrated sandbox escapes in AI coding agents
  • Exploits allow configurations written by attackers to run with trusted host privileges.
  • Agent security needs its own threat model, researchers say

AI coding agents may be tricked into turning on their operators and helping attackers compromise underlying systems, experts have warned.

Cybersecurity researchers Pillar looked at different methods to achieve the same results, finding that within months, Cursor, Codex, Gemini CLI, and Antigravity were all able to replicate sandbox exits and boundary bypasses.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top