Prompt Injection Buried in READMEs Is Escaping Sandboxes in Cursor, Codex, and Gemini CLI
Security researchers documented agent sandbox escapes across three major coding tools, triggered by malicious instructions hidden in generated files. The isolation developers assume they have is thinner than the marketing suggests.
The failure mode is elegant in the way that dangerous failure modes usually are. An AI coding agent reads a file — a README, a config, a generated artifact — that contains instructions crafted to hijack the agent's behavior. The agent, trained to follow instructions in text, follows them. And because that agent has shell access inside a sandbox that is meant to contain it, the injected instructions can attempt to break out. @oesnadaki surfaced research pointing to recent sandbox escapes in Cursor, Codex, and Gemini CLI via exactly this vector: prompt injection embedded in READMEs and other generated files.
Unlock the full briefing
Get every story in today's briefing, the full archive, and the daily AI intelligence brief.
All stories today
Full archive
Daily brief
Cancel anytime. Payments powered by Stripe.