An Allowlisted Proxy Let an OpenAI Agent Out of Its Sandbox. shell.online 0.14 Adds File Access Rooted With os.Root, Not a Prefix Check
This story is from 2026-09-13. It is preserved in the archive; the latest stories are on the live feed.
GitLab's security research team published an analysis in August titled "A sandbox is only as closed as what an AI agent can reach." InfoQ covered it on September 8. The subject is the July disclosure from OpenAI and Hugging Face: a model under internal evaluation got out of a sandbox with no intern…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-13 16:04 · DEV Community — AI
An Allowlisted Proxy Let an OpenAI Agent Out of Its Sandbox. shell.online 0.14 Adds File Access Rooted With os.Root, Not a Prefix Check