#sandbox

10 articles

Beware: Hermes Agent Security Audit Uncovers Credential Bypass, Sandbox Escape, and Session Hijacking in 5 HIGH-Severity Findings

A coordinated security audit of NousResearch/hermes-agent (EPIC #82591) revealed 5 HIGH-severity vulnerabilities including credent…

Beware: Claude Code Silently Drops Its Sandbox in Nested Project Folders

Claude Code issue #83035: when a session or subagent runs inside a nested project directory, the workspace's sandbox settings are …

Claude Code v2.1.223 Fixes Permission Bypasses: What the Security Patches Actually Did

Claude Code versions 2.1.221-223 (Aug 4-6, 2026) fixed hidden-command permission bypasses, sandbox escapes, and worktree isolation…

Beware: Claude Code CVE-2026-55607 — A Malicious Repo Can Escape the Sandbox and Execute Code on Your Machine

CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…

Beware: Your Coding Agent's Sandbox Was Leaking Its Own Credentials to Spawned Commands

A coordinated wave of security fixes across Gitlawb/zero and Goose shows the 'sandbox' you trusted was handing provider API keys, …

Three Show HN Tools That Show Where Coding Agents Are Headed: Memory, Sandboxes, and Reusable Context

This week's Hacker News surfaced three developer-built tools — capn-hook, agent-run, and Kote — that tackle the real pain points o…

Your Coding Agent's Sandbox Just Handed Out Your AWS Keys — Zero Bug Exposes Credential Leak

Gitlawb Zero's sandbox inherited environment variables verbatim from the parent process. AWS keys, GitHub tokens, database passwor…

Codex Sandbox Is Silently Dead on Windows — Smart App Control Is the Reason

Codex's Windows sandbox fails silently when Smart App Control is enabled. Every 'sandboxed' execution runs on bare metal — the UI …

gitlawb-zero Heads to 0.4.0 With a Native npm Binary and Tighter Sandbox

gitlawb-zero's 0.4.0 release prep ships its native binary as platform optionalDependencies, reworks Windows sandbox denial classif…

Codex Tightens Sandbox Enforcement for Memory Consolidation

A merged Codex commit preserves parent sandbox enforcement during memory consolidation — closing a path where a sub-process could …