Sandbox-Escape
Cloudflare Containers Bug Let One Tenant Read Another Tenant's Disk Data
A misconfigured Linux dm-thin storage pool let any Cloudflare Workers Paid customer recover unzeroed residual disk blocks from other tenants' Containers, Sandboxes, and Browser Rendering instances — exposing SQLite databases, .env files, and credentials.
BragJack: One Malicious Extension Hijacks AI Agents Across Five Major Browsers
Researcher Gal Weizman's BragJack proof-of-concept shows how a single malicious extension can hijack the built-in AI agents in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome, earning $20K+ in bounties and two CVEs (CVE-2026-0628, CVE-2026-55945).
CVE-2026-59971: MySQL MCP Server's SSE Mode Ships With No Auth, No Host Checks — CVSS 10
CVE-2026-59971 (CVSS 10) in the designcomputer mysql_mcp_server package leaves SSE/HTTP deployments wide open to unauthenticated SQL execution, reachable directly or via DNS rebinding, with no fix required beyond upgrading to 0.4.2.
NVIDIA NemoClaw Flaw Lets Any Website Hijack a Local AI Agent via DNS Rebinding
CVE-2026-65105 in NVIDIA NemoClaw lets a single malicious webpage use DNS rebinding to reach an unauthenticated local Ollama instance and permanently poison the model's chat template.
PraisonAI: Two More Critical RCEs (CVE-2026-61445, CVE-2026-61447) as AICoder Runs LLM Output Unsandboxed
PraisonAI's AICoder component writes files and executes shell commands straight from LLM tool calls with no path validation, and CodeAgent._execute_python() runs LLM-generated Python with no AST checks or sandboxing — two CVSS 9.9 and 10.0 flaws, patched in 4.6.78.
DuneSlide: Zero-Click Prompt Injection Chains to Full RCE in Cursor IDE (CVE-2026-50548, CVE-2026-50549)
Two critical Cursor IDE flaws, dubbed DuneSlide, let a poisoned MCP response or web search result steer the agent's own sandbox into overwriting its enforcement binary — zero-click prompt injection to unsandboxed remote code execution, patched in Cursor 3.0.