CICI/CD News
LatestAuthorsGlossary
Tag

#sandbox-escape

Tagged “sandbox-escape”

3 articles
Security & supply chain

The Codex sandbox escapes prove your agent's blast radius is your laptop

Two sandbox escapes in OpenAI Codex, named Heapjack and Overpatch, let attacker-controlled code run on the developer's host without an approval prompt. OpenAI fixed them in eight days; the architecture that made them possible is still standard.

Sep 22, 2026 · Tomás Vega
Supply chain security

The sandbox you thought was closed

The New Stack uses a July 16 intrusion at Hugging Face to name a security category that has been forming for a year: an AI agent breaking out of its containment. For CI/CD teams giving agents build-time access, the sandbox is one control, not the whole boundary.

Aug 25, 2026 · Tomás Vega
Supply-chain security

isolated-vm ships a sandbox escape, and the migration story catches up with itself

A type-confusion bug in isolated-vm's ExternalCopy transferList lets sandboxed JavaScript hijack the host process. The library that inherited vm2's job now inherits its threat model too.

Aug 21, 2026 · Tomás Vega
CICI/CD News

Independent CI/CD & deployment news — concise, vendor-neutral takes on pipelines, releases and DevOps tooling.

Network

GitHub ActionsJenkinsGitHubCI/CD Glossary

About

Latest newsAuthorsRSS feedSitemap