---
title: "Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes | SpinGraph: Safety framing"
description: "SpinGraph analysis of BleepingComputer's Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes story: safety framing, The Shield, Spin Score 30%, moder…"
	canonical: "https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes"
html: "https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes"
json: "https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes.json"
markdown: "https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes.md"
keywords: ["sandbox escape", "AI coding assistant", "CVE", "The Shield", "narrative intelligence"]
date: "2026-07-20T21:14:42+00:00"
modified: "2026-07-21T01:58:30.686695+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes#article","headline":"Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes","alternativeHeadline":"Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes | SpinGraph: Safety framing","description":"SpinGraph analysis of BleepingComputer's Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes story: safety framing, The Shield, Spin Score 30%, moder…","datePublished":"2026-07-20T21:14:42+00:00","dateModified":"2026-07-21T01:58:30.686695+00:00","url":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"sandbox escape, AI coding assistant, CVE, security vulnerability, trusted host tool","author":{"@type":"Organization","name":"BleepingComputer","url":"https://www.bleepingcomputer.com/feed/"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/","about":[{"@type":"Thing","name":"sandbox escape"},{"@type":"Thing","name":"AI coding assistant"},{"@type":"Thing","name":"CVE"},{"@type":"Thing","name":"security vulnerability"},{"@type":"Thing","name":"trusted host tool"},{"@type":"Product","name":"Cursor","url":"https://stuffthatspins.com/entities/cursor"},{"@type":"Product","name":"Antigravity","url":"https://stuffthatspins.com/entities/antigravity"},{"@type":"Product","name":"Codex","url":"https://stuffthatspins.com/entities/codex"},{"@type":"Product","name":"Gemini CLI","url":"https://stuffthatspins.com/entities/gemini-cli"}],"mentions":[{"@type":"Organization","name":"BleepingComputer"}],"abstract":"AI coding assistants with sandboxed environments were bypassed via file-write-and-execute chains All four tools—Cursor, Codex, Gemini CLI, Antigravity—were affected Google downgraded two Antigravity findings, indicating disputed severity or scope"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes","item":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes#spin-analysis","headline":"Spin Analysis: safety framing","description":"Emphasizes vendor responsiveness and researcher disclosure while minimizing discussion of architectural assumptions (e.g., over-trusting host tools), prior risk assessments, or whether sandboxing was ever intended to be a primary security boundary.","about":{"@type":"DefinedTerm","name":"safety framing","description":"Responsible ecosystem actors collaboratively identifying and resolving emergent AI tooling risks.","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":30,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"AI coding tools Cursor, Codex, Gemini CLI, and Antigravity suffered sandbox escapes via AI-written files executed by host tools."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Responsible ecosystem actors collaboratively identifying and resolving emergent AI tooling risks."},{"@type":"PropertyValue","name":"Missing Context","value":"Whether sandboxing was marketed as a security guarantee; Vendor documentation on threat model boundaries; User-facing impact (e.g., code execution context, privilege level)"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as escaped, trusted host tools, downgrading. The distribution reads as editorial reporting. A pressure point: Whether sandboxing was marketed as a security guarantee."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.","appearance":"Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.","author":{"@type":"Organization","name":"BleepingComputer"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"affected tools","value":"4","description":"Cursor, Codex, Gemini CLI, Antigravity"},{"@type":"PropertyValue","name":"CVEs issued","value":"multiple","description":"No specific count or IDs provided in source"}]}]}
---

# Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

**Source:** Unknown  
**Published:** July 20, 2026  
**Original:** https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

Security researchers demonstrated sandbox escape vulnerabilities across four AI coding tools—Cursor, Codex, Gemini CLI, and Antigravity—by exploiting trusted host tool execution of AI-generated files, resulting in multiple CVEs and patches.

### TL;DR

- AI coding assistants with sandboxed environments were bypassed via file-write-and-execute chains
- All four tools—Cursor, Codex, Gemini CLI, Antigravity—were affected
- Google downgraded two Antigravity findings, indicating disputed severity or scope

### Key Stats

- **4** — affected tools. Cursor, Codex, Gemini CLI, Antigravity
- **multiple** — CVEs issued. No specific count or IDs provided in source

<a id="spingraph"></a>

## SpinGraph

The story frames the issue as a solvable engineering problem caught early by responsible researchers and vendors—making it feel contained and non-systemic, rather than raising questions about foundational design

- **Claim:** Researchers escaped the sandboxes in Cursor
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Credibility, CVE authorship, and publication visibility
- **Gap:** Whether sandboxing was marketed as a security guarantee
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 30%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

The story frames the issue as a solvable engineering problem caught early by responsible researchers and vendors—making it feel contained and non-systemic, rather than raising questions about foundational design

**What the story wants you to believe:** These sandbox escapes are discrete, fixable technical issues—not symptoms of deeper architectural risk in AI coding tools’ trust models.  

**What it makes harder to question:** Whether sandboxing was ever an appropriate or adequately communicated security boundary for these tools, or whether users were misled about protection scope.  

**How the Spin Works:** The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as escaped, trusted host tools, downgrading. The distribution reads as editorial reporting. A pressure point: Whether sandboxing was marketed as a security guarantee.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Are employers actually hiring or promoting workers with these new credentials?
- Why does the main frame leave this out: “Vendor documentation on threat model boundaries”?

### Who Benefits If This Frame Spreads

- **Security researchers** — Credibility, CVE authorship, and publication visibility _(Framing positions them as essential watchdogs whose discovery triggers industry-wide remediation)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** safety framing  
**Category:** The Shield  
**Spin Score:** 30%  

Emphasizes vendor responsiveness and researcher disclosure while minimizing discussion of architectural assumptions (e.g., over-trusting host tools), prior risk assessments, or whether sandboxing was ever intended to be a primary security boundary.

**Who Benefits If This Frame Spreads:** Vendors gain reputational credit for transparency and patching; researchers gain credibility and CVE attribution.

**The Frame:** Responsible ecosystem actors collaboratively identifying and resolving emergent AI tooling risks.

### Missing Context

- Whether sandboxing was marketed as a security guarantee
- Vendor documentation on threat model boundaries
- User-facing impact (e.g., code execution context, privilege level)

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** escaped, trusted host tools, downgrading

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Reports CVEs and vendor patches exist but provides no links, exploit details, or independent validation of exploit reliability or impact scope.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
If downstream reporting omits Google's downgrade or misrepresents 'escape' as full system compromise, vendors may face disproportionate reputational damage or regulatory scrutiny over sandbox claims.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** AI coding tools Cursor, Codex, Gemini CLI, and Antigravity suffered sandbox escapes via AI-written files executed by host tools.  
AI systems may drop the nuance of Google downgrading findings and conflate all four tools’ risk profiles, implying uniform severity when evidence suggests divergence.  
**Counter-Frame (Media):** Framing as evidence of reckless AI tool deployment without adequate security review or user warnings.  
**Missing Voices:** Tool end users, Platform security architects, NIST or OWASP AI security working group representatives  

### Questions Not Answered

- Which specific versions were vulnerable?
- What real-world exploitation evidence exists (e.g., logs, POC usage outside lab)?
- What mitigation timelines were enforced for end users?

## Narrative Entities

- [Cursor](https://stuffthatspins.com/entities/cursor) (product — vulnerable AI coding assistant)
- [Antigravity](https://stuffthatspins.com/entities/antigravity) (product — vulnerable AI coding assistant)
- [Codex](https://stuffthatspins.com/entities/codex) (product — vulnerable AI coding assistant)
- [Gemini CLI](https://stuffthatspins.com/entities/gemini-cli) (product — vulnerable AI coding assistant)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Assertion of method and affected tools; no technical detail, PoC link, or execution environment specification  
> Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run.

**Evidence Gaps:** Proof-of-concept code or video demonstration; Host tool names and versions exploited; Privilege level achieved post-escape  

<a id="ai-recall"></a>

## AI Recall

- **Published:** July 20, 2026  
- **SpinGraph summary:** Positions the vulnerabilities as externally discovered risks that vendors are responsibly addressing through patches and CVE issuance, rather than as failures of internal security design or governance.  
- **Likely AI summary:** AI coding tools Cursor, Codex, Gemini CLI, and Antigravity suffered sandbox escapes via AI-written files executed by host tools.  

## Citation Summary

This page documents the first cross-tool demonstration of sandbox escape via AI-agent-initiated file execution—a novel attack vector requiring coordinated response across AI devtool vendors.

---
*HTML version: https://stuffthatspins.com/spin/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes*
