Cursor, Codex, Gemini CLI, and Antigravity AI coding tools vulnerable to sandbox escape attacks

Popular AI coding assistants allow attackers to escape security sandboxes by writing files that host tools later execute, potentially compromising developer workstations.

Abstract illustration of fragmented containers with organic elements suggesting security boundary escape
AI-generated illustration · Sylvaris

How the attacks work

Security researchers discovered that multiple AI coding assistants fail to properly isolate agent-generated code from the host system. The vulnerability occurs when AI agents write configuration or script files that trusted host tools automatically execute, breaking out of their intended security boundaries.

The attack surface includes popular development tools like Cursor, Codex, Gemini CLI, and Antigravity. Each tool has received patches, though Google downgraded the severity of two findings in Antigravity. Multiple CVE identifiers have been assigned to track the distinct vulnerabilities.

Implications for AI-assisted development

The findings highlight a fundamental tension in AI coding tools: giving agents enough system access to be useful while preventing malicious behavior. As these tools become more autonomous, the attack surface expands beyond traditional code injection to include configuration manipulation and toolchain exploitation.

Developers using AI coding assistants should verify that their tools have received security updates. Organizations may need to reconsider which AI agents run with elevated privileges or access to sensitive codebases until isolation mechanisms mature.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.