---
title: Sandbox-Escape Flaws Turned Up in Every Major AI Coding Agent This Summer
description: Researchers disclosed sandbox-escape bugs across Claude Code, Codex, Cursor and Gemini CLI this summer. The vendors patched, and bounding an agent's reach is a deployment choice.
author: Darie Nani (Editor-in-Chief)
updated: 2026-09-10T23:29:49.521Z
canonical: https://www.sovereignmagazine.com/article/ai-coding-agents-sandbox-escape-security-2026
image: https://cdn.nanimediahouse.com/pexels-close-up-view-of-a-developer-typing-code-on-a-keyboard-with--36497969.jpg
categories: Artificial Intelligence
content_type: Analysis
region: Global
publication: Sovereign Magazine
access: members
schema_type: Article
---

Over several weeks this summer, security teams disclosed sandbox-escape vulnerabilities in nearly every major AI coding agent that engineers now run against real code: Anthropic's Claude Code, OpenAI's Codex, Cursor and Google's Gemini CLI. Pillar Security, which reported several of the flaws, called the run of disclosures a [week of sandbox escapes](https://www.pillar.security/blog/the-week-of-sandbox-escapes). Every vendor named received the reports and shipped fixes. The disclosures share a single mechanism: an agent confined to a sandbox can still reach the host machine around it. They land as more engineering teams hand these agents write access to production repositories.

## The Disclosures Came From Several Independent Teams, Not One

A stealth security startup called Accomplish, founded by Amit Avner and Or Hiltch, disclosed two of the vulnerabilities, both in Anthropic's tools. The first, which Accomplish named [Beltdown](https://accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/), affected Claude Code. The second, SharedRoot, affected Claude Cowork and reached roughly 500,000 macOS users before it was patched. Accomplish reported Beltdown to Anthropic on July 13, 2026. Anthropic triaged it the same day, shipped a partial patch on August 6, and delivered a full fix on August 26 in Claude Code version 2.1.247, roughly 44 days from report to complete remediation.

---

*This article is only available to registered readers. Visit the article URL to read the full piece.*
