AI coding tools leak secrets through sandbox vulnerabilities
Source: Upstartsmedia
Anthropic's Claude, OpenAI's Codex, and Cursor's IDE all have documented sandbox escape routes that let attackers extract training data, API keys, and proprietary code. The vulnerabilities remain largely unpatched because disclosure would crater enterprise adoption before these tools achieve critical market share. The problem mirrors early browser security: vendors are prioritizing feature velocity and market penetration over the kind of boring, expensive hardening that would slow down sales cycles, leaving developers who trust these tools to handle sensitive work functionally exposed.