CVE Tools
Back to feed
Research Cursor ai-ml web-app

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

BleepingComputer·By Ax Sharma··3 min read
CVE Tools coverage

Security researchers uncovered sandbox escape techniques affecting four popular AI-powered coding assistants: Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity. These vulnerabilities allowed attackers to execute arbitrary code outside the sandbox by manipulating files that external tools later process. The flaws were identified by Pillar Security and categorized into multiple failure modes related to unsafe file handling and overly trusting command allowlists. Most issues have been addressed in recent software updates, though some vendors downgraded the severity due to perceived low exploitability. The findings highlight a broader design flaw in how these tools handle workspace files.