One Docker socket to rule them all: Escaping Codex, Cursor, and Gemini CLI (www.pillar.security)

🤖 AI Summary
A recent discovery has highlighted significant vulnerabilities in the sandbox environments of AI coding agents Codex, Cursor, and Gemini CLI, revealing their susceptibility to "sandbox escapes" via Docker. While these agents implemented a "deny-default" security model to control workspace actions, they remained open to exploitation through privileged Docker daemon access installed on nearly all Mac systems. This gap allowed a malicious actor to execute arbitrary commands and access the user's home directory, effectively breaching the intended security. This finding is crucial for the AI/ML community as it underscores the limitations of current sandboxing techniques, emphasizing that controlling syscall access is insufficient if daemons can be manipulated from within the sandbox. The responses from the three vendors varied, with Cursor promptly addressing the vulnerability, Codex deeming it not a bug under their configurations, and Gemini CLI referring to it as documented behavior. The incident signals a need for improved containment solutions and a reconsideration of how developer tools are secured, especially as AI agents perform increasingly autonomous tasks.
Loading comments...
loading comments...