{"id":8833,"date":"2026-07-21T11:46:02","date_gmt":"2026-07-21T11:46:02","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8833"},"modified":"2026-07-21T11:46:02","modified_gmt":"2026-07-21T11:46:02","slug":"ai-agents-can-escape-sandboxes-without-ever-breaking-them","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8833","title":{"rendered":"AI agents can escape sandboxes without ever breaking them"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Sandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. <\/p>\n<p class=\"wp-block-paragraph\">Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and Antigravity can indirectly cross security boundaries without technically escaping their sandboxes.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn almost every case, the agent did not need to break the sandbox directly,\u201d the researchers said in a blog post. \u201cIt only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The findings outlined four specific and repeatable failure modes in AI sandboxes. These included denylist sandboxes failing growing OS complexity, workspace configurations turning out to be executable code, command allowlists trusting command names instead of invocations, and privileged local daemons that sit outside the sandbox entirely.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCISOs and security buyers need to realize that it\u2019s not enough for an agentic IDE or CLI to have a sandbox,\u201d the researchers said, adding that it is important to know where the sandbox\u2019s actual boundary is.<\/p>\n<h2 class=\"wp-block-heading\">Escaping sandboxes without breaking them<\/h2>\n<p class=\"wp-block-paragraph\">Pillar challenged the basic understanding of sandboxing in AI-assisted development. Rather than escaping through kernel exploits or container breakouts, the demonstrated attacks relied on an indirect mechanism.<\/p>\n<p class=\"wp-block-paragraph\">In all shown attack paths, the agent remains confined while producing files that trusted host-side applications subsequently consume.<\/p>\n<p class=\"wp-block-paragraph\">Those files may include workspace configuration, automation scripts, IDE settings, and virtual environment contents that naturally participate in a developer\u2019s workflow. When external tools later execute or interpret those files outside the sandbox, code originating from within the isolated environment effectively crosses the security boundary without violating the sandbox\u2019s rules.<\/p>\n<h2 class=\"wp-block-heading\">Different sandbox escapes for different agents<\/h2>\n<p class=\"wp-block-paragraph\">Pillar demonstrated the pattern across multiple AI coding tools using different techniques. In Antigravity, the researchers <a href=\"https:\/\/www.pillar.security\/blog\/escaping-antigravitys-allow-default-seatbelt\" target=\"_blank\" rel=\"noopener\">exploited<\/a> weaknesses in the denylist-style macOS Seabelt profile and abused VS Code task configurations that were later executed outside the sandbox. Cursor, meanwhile, was shown to trust agent-created <a href=\"https:\/\/www.pillar.security\/blog\/the-sandbox-let-me-edit-a-venv-and-something-else-ran-it\" target=\"_blank\" rel=\"noopener\">Python virtual environments<\/a>, alternate <a href=\"https:\/\/www.pillar.security\/blog\/git-directories-do-not-have-to-be-called-git\" target=\"_blank\" rel=\"noopener\">Git directories<\/a>, and workspace <a href=\"https:\/\/www.pillar.security\/blog\/the-hook-was-already-in-the-workspace\" target=\"_blank\" rel=\"noopener\">hook configurations <\/a>that ultimately ran with host privileges.<\/p>\n<p class=\"wp-block-paragraph\">The researchers also found a <a href=\"https:\/\/www.pillar.security\/blog\/one-docker-socket-to-rule-them-all-escaping-codex-cursor-and-gemini-clis-sandboxes\" target=\"_blank\" rel=\"noopener\">common escape path<\/a> affecting Cursor, Codex CLI, and Gemini CLI through Docker Desktop\u2019s privileged daemon, allowing sandboxed agents to execute commands outside their restricted environments.<\/p>\n<p class=\"wp-block-paragraph\">In another Codex CLI finding, a supposedly safe Git allowlist could be manipulated to modify repository configuration and trigger code execution at a later stage.<\/p>\n<h2 class=\"wp-block-heading\">Agentic development demands a different security model<\/h2>\n<p class=\"wp-block-paragraph\">Pilar argued that enterprises need a new security model for agentic software. The existing endpoint protections typically focus on whether a process can escape its execution environment. But autonomous agents challenge this by continuously generating content that other trusted systems consume.<\/p>\n<p class=\"wp-block-paragraph\">The researchers recommended treating workspace configurations that can trigger execution as sensitive assets, requiring explicit approval before agents create or modify host-side automation, ensuring that helper processes operate under the same security policy as direct agent execution, and preserving provenance that distinguishes user-created files from repository- or agent-generated content. <\/p>\n<p class=\"wp-block-paragraph\">Organizations were also advised to model security policies around command side effects rather than simply process invocation, limit access to privileged local services, and monitor trust handoffs throughout the development workflow.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Sandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and Antigravity can indirectly cross security boundaries without technically escaping their sandboxes. [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8834,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8833","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8833"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8833"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8833\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8834"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}