Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
A symlink flaw in Claude Code's sandbox allows escape from containment, potentially enabling code execution on the host. This vulnerability was referenced…
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
AI Code EditorAim SecurityCato AI LabsCheck Point Research
X41 D-Sec independently found a sandbox escape path in LiteLLM's Custom Code Guardrail playground endpoint, which bypassed a regex deny-list through runtime…
CVE-2026-40217 is a sandbox escape vulnerability in LiteLLM's Custom Code Guardrail, where Python's exec() function is used without proper filtering, allowing attackers…