- Sources: Pillar Security writeup, BleepingComputer, Cursor advisory GHSA-v4xv-rqh3-w9mc, HN 49003857
- Summary: Pillar Security published on 2026-07-20 a sandbox-escape technique against coding-agent CLIs (Cursor, Codex, Gemini CLI, Antigravity). Deny-default sandbox profiles block file writes outside the workspace but still allow process execution and reading the Docker Desktop socket. An agent (or injected instruction) can
curl an Alpine rootfs into the workspace, docker import it to bypass registry restrictions, run a --privileged container, mount the host filesystem over VirtioFS, and write to files like .zshrc, reaching SSH keys and credentials outside the sandbox. Cursor shipped a fix restricting Docker-socket and Launch Services access (GHSA-v4xv-rqh3-w9mc). Codex marked it informational and configuration-dependent, and Gemini CLI declined to fix, citing documentation. - Why it matters: It shows agent sandboxes cannot contain what a privileged local daemon does on the agent's behalf, so a Docker install undercuts the sandbox that coding agents rely on for autonomous execution.
- Follow-up: Watch for Codex and Gemini CLI mitigations and whether other agents that read the Docker socket are affected.
send feedback on this story