BREAKING
AI Coding Agents Escape Sandboxes
Four Tools Tested by Pillar
Cursor
IDE
●
Virtualenv tamper
●
Git spoof via fsmonitor
Codex, Gemini, Antigravity
CLI/IDE
●
Docker socket escape
●
VSCode task abuse
How the Escape Works
1
Agent writes workspace config
↓
2
Host tool trusts the files
↓
3
Code runs on the host
0
boundary failures
0
agents affected
0
CVE-2026-50548 CVSS
Sandbox Trust Under Scrutiny
AI NEWS BLITZ
Researchers say four popular AI coding agents can break out of their sandboxes.