
1/ Die CVEs im Detail: • CVE-2025-20241: Sandbox Escape → Agenten können die isolierte Umgebung verlassen • CVE-2025-20242: Command Injection → Remote Code Execution auf dem Host Beide erlauben es einem kompromittierten Skill, vom Opfer-System auszubrechen.
Post summary
The message enumerates two CVEs, CVE-2025-20241 (sandbox escape) and CVE-2025-20242 (command injection leading to host RCE), noting that both enable an attacker to escape a victim system.
