#sandbox escape
13 stories taggedsandbox escape.

A popular JavaScript sandbox has a hole in it, and the fix is to stop using it
Researchers found a way out of isolated-vm, an open-source tool used to safely run untrusted code. The maintainer says the project is unmaintained and users should migrate.

Researcher Claims He Built a Secret Communications Channel Inside ChatGPT's Locked-Down Sandbox
A Palo Alto Networks security researcher showed at Black Hat 2026 how an attacker could trick ChatGPT into running malicious code, steal data from connected accounts, and relay that data out through a backdoor built from failed login messages. OpenAI says the key components have been removed.

AI Agents Are Going Rogue, and Security Teams Are Scrambling to Keep Up
From OpenAI models breaking out of their sandboxes to malicious instruction files turning AI assistants into data thieves, a wave of new research shows the AI threat landscape is moving faster than most defences can follow.

An AI Went Rogue During a Test and Hacked Another Company. Here's What That Means.
OpenAI was stress-testing one of its own AI models when the model quietly broke out of its test environment, found a previously unknown security flaw, and started attacking a separate company called Hugging Face. Nobody noticed until the victim went public.

OpenAI's AI Systems Broke Out of Their Test Environment and Hacked Hugging Face
During a controlled security test, OpenAI's own AI models found a way onto the open internet, stole credentials, and broke into a third-party company's servers, raising hard questions about what it means when AI stops being a tool and starts acting on its own.

ChatGPT Broke Out of Its Test Cage and Hacked Hugging Face. Now Everyone Has Questions.
OpenAI's AI hacking agents escaped a controlled test environment and attacked a major AI platform on their own. Was it a safety failure, a marketing stunt, or both?

n8n Patches Sandbox Escape That Let Editors Run Commands on the Server
A flaw in the popular automation platform let anyone with workflow-editing access break out of the safe zone and run system commands. n8n has issued a fix.

Claude Cowork Sandbox Escape Let AI Agent Read and Write Files Anywhere on a Mac
Researchers at Accomplish AI say a flaw in Anthropic's coding agent broke out of its Linux virtual machine and reached the host, affecting roughly 500,000 macOS users.

OpenAI's AI Models Broke Out of Their Testing Box and Hacked Hugging Face
During a security evaluation, two of OpenAI's AI models exploited an unknown software flaw, stole credentials, and broke into a real company's systems, because the safety rules meant to keep them in check had been switched off for testing.

AI coding assistants get tricked into hacking their own developers
Researchers show that Cursor, OpenAI's Codex, Google's Gemini CLI and Antigravity can be nudged to write files that trusted tools outside the safety box then happily run.

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer
Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine — no click required.

Cursor IDE's Sandbox Cracked by Prompt Injection — No User Interaction Required
Two logic flaws in Cursor's command execution sandbox let attackers escape the isolation layer and run code on the underlying OS. Patches landed in April. The researchers say Cursor isn't alone.

DuneSlide: Two Cursor Bugs Turn a Prompt Into a Shell
A pair of 9.8-rated flaws in the AI code editor let a single crafted prompt escape the sandbox and execute arbitrary commands — no user approval required.