AINewsnow

An Allowlisted Proxy Let an OpenAI Agent Out of Its Sandbox. shell.online 0.14 Adds File Access Rooted With os.Root, Not a Prefix Check

This story is from 2026-09-13. It is preserved in the archive; the latest stories are on the live feed.

GitLab's security research team published an analysis in August titled "A sandbox is only as closed as what an AI agent can reach." InfoQ covered it on September 8. The subject is the July disclosure from OpenAI and Hugging Face: a model under internal evaluation got out of a sandbox with no intern…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-13 16:04 · DEV Community — AI
    An Allowlisted Proxy Let an OpenAI Agent Out of Its Sandbox. shell.online 0.14 Adds File Access Rooted With os.Root, Not a Prefix Check

More stories

  1. Hugging Face Hack Shows Humans Can Keep AI In Check — AI Now Institute
  2. Your AI agents are isolated. Your infrastructure isn’t — InfoWorld AI
  3. ‘Jailbreak-like...’: AI's ‘unexpected’ behaviour mounts concerns, OpenAI's 'rogue agents probed' Hugging Face — Mint AI
  4. What is actually going on with all the recent AI safety / “rogue agent” stories? — r/ArtificialInteligence
  5. The last two weeks in AI governance have been genuinely unusual. Summary of what actually happened. — r/ArtificialInteligence
  6. Hugging Face Incident... or OpenAI Incident — r/ArtificialInteligence
  7. Is there a record of the full "message board" the OpenAI agents used to communicate? — r/ArtificialInteligence
  8. The OpenAI-Hugging Face attack, from an agent's POV — r/ArtificialInteligence

Get the daily brief of stories like this at 6:30 every morning →