Skip to main content

Security Risks from AI Coding Agents Expand Beyond the Sandbox: Pillar

AI coding assistants have become an essential part of developers’ work, automating many of the repetitive tasks – think boilerplate coding and scaffolding – that in the past ate up a lot of their time. More jobs can now get done faster.

That said, such agents also represent a significant security risk, making developers – who were already targets of cybercriminals – even more attractive. In recent weeks, cybersecurity researchers have reported on such threats as “HalluSquatting” and “GhostApproval,” which target developers and their AI tools.

That’s in part because the adoption of AI coding agents is outpacing the development of security tools to protect them. Cyberhaven Lab researchers noted in May that adoption of AI coding agents was growing faster than the use of any other AI tool, jumping 357% between February 2025 and this year. They also are the highest-risk category.

“When a developer pastes a code block into a coding assistant, or when an agentic coding tool browses a local repo autonomously, the data exposure isn’t hypothetical,” wrote Mike Leon, machine learning engineer with Cyberhaven. “It’s immediate. Security teams that haven’t built specific detection and policy coverage for coding assistant activity are operating with a significant blind spot, one that is growing by hundreds of users per quarter.”

The Threat Outside of the Sandbox

Over the past several months, Pillar Security researchers have written about a range of security flaws in the sandboxes of four popular coding agents – Google’s Gemini CLI, OpenAI’s Codex, Cursor, and Antigravity – that can be abused without directly targeting the sandboxes themselves. Instead, the coding agents needed only to create files that a trusted component outside of the sandbox would later be processed – run, loaded, scanned, and treated as safe – by a trusted component outside of the sandbox.

“In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up,” researchers Eilon Cohen, Dan Lisichkin, and Ariel Fogel wrote in a report this week dubbed “The Week of Sandbox Escapes.” “The bottom line is that an agent’s blast radius is not the agent process; it includes everything the agent can write that the host later trusts.”

The AI agents themselves can work – and remain – in the sandbox, so the issue isn’t a standard escape. The problem is the files an agentic CLI or IDE produce inside the sandbox can be read and acted upon outside of it. Coding agents run their own tools outside of the sandbox, from Python extensions that resolve interpreters and Git integrations that scan repositories to VS Code running task files, hook engines firing lifecycle commands, and Docker Desktop exposing local sockets.

Prompt Injection Threat

Given that, untrusted input created via a prompt injection attack – such as malicious code in a README file, web content, a software dependency, or code comments – can be processed by the agent within the sandbox and acted upon outside of it. It’s another way that threat actors can abuse the trust inherent in AI coding tools.

Pillar researchers categorized their findings into four “failure modes,” including denylist sandboxes that aren’t keeping up with the increasing complexity in operating systems and workspace configurations that essentially are executable code. The others are so-called safe command allowlists that trust command names rather than invocations and privileged local daemons that are located outside of the sandbox.

The Security Flaws

Four of the flaws were found in Cursor, including one in which Git metadata indirection – using a pointer file instead of a Git folder – escaped the sandbox’s path-based security rules, and another in which the agentic assistant could modify a virtual environment so that a Python extension could execute the changed interpreter. A third vulnerability – tracked as CVE-2026-48124 and fixed in version 3.0.0 – could turn a workspace-control Claude hook configuration file into a tool for executing commands outside of a sandbox.

A vulnerability affecting Cursor, Codex, and Gemini CLI at the same time allowed agents to launch privileged containers and let a privileged local daemon become a code execution environment outside of a sandbox. Like the others, this flaw has been fixed.

OpenAI patched a vulnerability in Codex CLI in which a “safe” command allowlist trusted a command name “without modeling dangerous arguments and Git side effects.”

Pillar also downgraded two issues in Antigravity – a sandbox bypass and a macOS Seatbelt denylist bypass – saying they were difficult to exploit.

An Ongoing Concern

Other researchers also have been investigating the risks of AI coding agents running inside a sandbox. Cymulate’s research lab in May detailed similar sandbox-related issues with Anthropic’s Claude Code, Gemini CLI, Codex CLI, Cursor, and GitHub Copilot. Pillar’s research also echoes the concerns outlined by Cymulate.

“AI coding agents … are rapidly becoming part of modern development workflows,” the researchers wrote. “These tools are often marketed not only as productivity tools, but also as security tools capable of auditing code, detecting vulnerabilities and improving overall security posture. This research shows that the agents themselves introduce a new attack surface.”



from DevOps.com https://ift.tt/rn6fgjq

Comments

Popular posts from this blog

Your Wednesday Briefing

Your Wednesday Briefing By Natasha Frost from NYT Briefing https://ift.tt/3sTrkl7

LogicMonitor Introduces Unlimited Log Data Retention

LogicMonitor today announced it will provide an option that allows IT organizations to retain an unlimited amount of log data on its software-as-a-service (SaaS) platform. Tej Redkar, chief product officer at LogicMonitor, said one of the issues that is holding back advances in observability is the cost of storing log data. LogicMonitor has decided to […] The post LogicMonitor Introduces Unlimited Log Data Retention appeared first on DevOps.com . from DevOps.com https://ift.tt/30zibWO

Remedy and Transformation

The post Remedy and Transformation appeared first on DevOps.com . from DevOps.com https://ift.tt/3afU4fx