Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Positions the vulnerabilities as externally discovered risks that vendors are responsibly addressing through patches and CVE issuance, rather than as failures of internal security design or governance.
View original on bleepingcomputer.comOverview
Security researchers demonstrated sandbox escape vulnerabilities across four AI coding tools—Cursor, Codex, Gemini CLI, and Antigravity—by exploiting trusted host tool execution of AI-generated files, resulting in multiple CVEs and patches.
TL;DR
- AI coding assistants with sandboxed environments were bypassed via file-write-and-execute chains
- All four tools—Cursor, Codex, Gemini CLI, Antigravity—were affected
- Google downgraded two Antigravity findings, indicating disputed severity or scope
Key Stats
4
affected tools
Cursor, Codex, Gemini CLI, Antigravity
multiple
CVEs issued
No specific count or IDs provided in source
Questions Answered
Keywords
Narrative Frame
safety framing
Spin Score
30%
Emphasizes vendor responsiveness and researcher disclosure while minimizing discussion of architectural assumptions (e.g., over-trusting host tools), prior risk assessments, or whether sandboxing was ever intended to be a primary security boundary.
What the story wants you to believe
These sandbox escapes are discrete, fixable technical issues—not symptoms of deeper architectural risk in AI coding tools’ trust models.
What it makes harder to question
Whether sandboxing was ever an appropriate or adequately communicated security boundary for these tools, or whether users were misled about protection scope.
How the spin works
The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as escaped, trusted host tools, downgrading. The distribution reads as editorial reporting. A pressure point: Whether sandboxing was marketed as a security guarantee.
Who Benefits If This Frame Spreads
Security researchers
Credibility, CVE authorship, and publication visibility
Framing positions them as essential watchdogs whose discovery triggers industry-wide remediation
The Frame
Responsible ecosystem actors collaboratively identifying and resolving emergent AI tooling risks.
Missing Context
- Whether sandboxing was marketed as a security guarantee
- Vendor documentation on threat model boundaries
- User-facing impact (e.g., code execution context, privilege level)
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The story frames the issue as a solvable engineering problem caught early by responsible researchers and vendors—making it feel contained and non-systemic, rather than raising questions about foundational design
- Claim
Researchers escaped the sandboxes in Cursor
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.
- Frame
Blame shifts elsewhere
Responsible ecosystem actors collaboratively identifying and resolving emergent AI tooling risks.
- Beneficiary
Credibility, CVE authorship, and publication visibility
Security researchers — Credibility, CVE authorship, and publication visibility
- Gap
Whether sandboxing was marketed as a security guarantee
- AI Risk
AI may repeat the headline as fact
AI coding tools Cursor, Codex, Gemini CLI, and Antigravity suffered sandbox escapes via AI-written files executed by host tools.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. | Assertion of method and affected tools; no technical detail, PoC link, or execution environment specification | Claim Present in Source | High | Proof-of-concept code or video demonstration; Host tool names and versions exploited; Privilege level achieved post-escape |
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.
evidence: Assertion of method and affected tools; no technical detail, PoC link, or execution environment specification
"Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run."
Evidence Gaps
- Proof-of-concept code or video demonstration
- Host tool names and versions exploited
- Privilege level achieved post-escape
Fact Check Signals
0 of 1 claim matched · confidence: low · checked July 21, 2026
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
BleepingComputer · Media
Counter-Frames
Brand Frame
Responsible ecosystem actors collaboratively identifying and resolving emergent AI tooling risks.
Media / Reader Counter-Frame
Framing as evidence of reckless AI tool deployment without adequate security review or user warnings.
Regulatory Counter-Frame
Highlighting failure to meet basic secure-by-design expectations for developer-facing AI tools handling local filesystem access.
AI Summary Frame
Omitting downgrade context and presenting all four tools as equally compromised, reinforcing false equivalence in risk posture.
Missing Voices
Questions Not Answered
- Which specific versions were vulnerable?
- What real-world exploitation evidence exists (e.g., logs, POC usage outside lab)?
- What mitigation timelines were enforced for end users?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
36
Trigger score 30
Triggered by: Major AI entity
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"AI coding tools Cursor, Codex, Gemini CLI, and Antigravity suffered sandbox escapes via AI-written files executed by host tools."
Concern: AI systems may drop the nuance of Google downgrading findings and conflate all four tools’ risk profiles, implying uniform severity when evidence suggests divergence.
-
Published
Jul 20, 2026
-
Ingested
Jul 21, 2026
-
SpinGraph Created
Jul 21, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_cursor_codex_gemini_cli_antigravity_hit_by_sandb
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from BleepingComputer
View all →- Windows LegacyHive zero-day flaw gets free, unofficial patches
- Microsoft shares manual fix for WSUS sync delays and timeouts
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
- US seizes over 1,000 websites in FIFA World Cup piracy crackdown
- Hackers steal $23.7 million in crypto from Ostium in off-chain attack
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO