Prompt Injection Buried in READMEs Is Escaping Sandboxes in Cursor, Codex, and Gemini CLI

Security researchers documented agent sandbox escapes across three major coding tools, triggered by malicious instructions hidden in generated files. The isolation developers assume they have is thinner than the marketing suggests.

The failure mode is elegant in the way that dangerous failure modes usually are. An AI coding agent reads a file — a README, a config, a generated artifact — that contains instructions crafted to hijack the agent's behavior. The agent, trained to follow instructions in text, follows them. And because that agent has shell access inside a sandbox that is meant to contain it, the injected instructions can attempt to break out. @oesnadaki surfaced research pointing to recent sandbox escapes in Cursor, Codex, and Gemini CLI via exactly this vector: prompt injection embedded in READMEs and other generated files.

Unlock the full briefing

Get every story in today's briefing, the full archive, and the daily AI intelligence brief.

All stories today

Full archive

Daily brief

Cancel anytime. Payments powered by Stripe.