#sandbox-escape
Tagged “sandbox-escape”
3 articlesSecurity & supply chain
The Codex sandbox escapes prove your agent's blast radius is your laptop
Two sandbox escapes in OpenAI Codex, named Heapjack and Overpatch, let attacker-controlled code run on the developer's host without an approval prompt. OpenAI fixed them in eight days; the architecture that made them possible is still standard.
Sep 22, 2026 · Tomás VegaSupply chain securityThe sandbox you thought was closed
The New Stack uses a July 16 intrusion at Hugging Face to name a security category that has been forming for a year: an AI agent breaking out of its containment. For CI/CD teams giving agents build-time access, the sandbox is one control, not the whole boundary.
Aug 25, 2026 · Tomás VegaSupply-chain securityisolated-vm ships a sandbox escape, and the migration story catches up with itself
A type-confusion bug in isolated-vm's ExternalCopy transferList lets sandboxed JavaScript hijack the host process. The library that inherited vm2's job now inherits its threat model too.
Aug 21, 2026 · Tomás Vega