
1/ Die CVEs im Detail: • CVE-2025-20241: Sandbox Escape → Agenten können die isolierte Umgebung verlassen • CVE-2025-20242: Command Injection → Remote Code Execution auf dem Host Beide erlauben es einem kompromittierten Skill, vom Opfer-System auszubrechen.
Post summary
The passage describes two new CVEs—CVE‑2025‑20241 (sandbox escape) and CVE‑2025‑20242 (command injection leading to RCE)—and notes that either vulnerability allows a compromised skill to escape the victim system.
