MyPrivateClaw

AI Coding Tools Cursor, Codex CLI, Gemini CLI, and Antigravity Affected by Sandbox Escapes

Multiple sandbox escape vulnerabilities were identified across AI coding assistants, including Cursor Desktop, OpenAI Codex CLI, Google Gemini CLI, and Antigra…

Published on MyPrivateClaw

Jul 21, 2026, 3:17 PM UTC

Coverage date

Jul 20, 2026

Last updated

Jul 22, 2026, 11:52 PM UTC

News summary

Cursor Desktop versions 2.4.37 through 2.x allowed an agent running in Auto Run Sandbox mode to execute workspace defined Claude hook commands from .claude/settings.local.json without dedicated user approval, enabling sandbox escape; this was assigned CVE 2026 48124 and fixed in version 3.0.0. This finding is bounded to Cursor Desktop on macOS; workspace sourced hook commands now require approval post fix. The advisory notes a High severity CVSS score of 8.5. Cursor IDE for macOS allowed an agent running in Auto Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper, which the Microsoft Python extension then invoked outside the sandbox; this issue (GHSA p9g2 cr55 cw9c) was fixed in version 3.1.2. No assigned CVE; reported by @Danus365; affects versions <3.1.2. A Docker socket sandbox escape finding (GHSA v4xv rqh3 w9mc) affected Cursor, OpenAI's C…