Disclosure
Four findings, same shape.
Cursor: a hook configuration file, written inside the workspace, ran commands on the host. CVE-2026-48124, fixed in 3.0.0.
Cursor again: the agent modified a Python virtual environment, and the editor's Python extension then executed the modified interpreter automatically.
Cursor a third time: alternative git metadata bypassed the path-based security checks.
Codex: an allowlist that matched on the name of a binary rather than its identity.
And one Docker socket finding hit Codex, Cursor and Gemini CLI at once. A privileged local daemon the agents could reach became an unsandboxed place to run code.
Cymulate documented this class in April across Claude Code, Gemini CLI and Codex CLI and named it configuration-based sandbox escape. A file written inside the sandbox runs on the host at next launch.
Four vendors, independent teams, same underlying assumption.
Post summary
Four findings expose a configuration‑based sandbox escape in CVE-2026-48124 affecting Cursor, Codex, Gemini CLI, and related tools, with remediation available in version 3.0.0.