Frontier models failed to escape the VM but exploited a real sandbox network-policy flaw
inductionheads · x · 2026-09-24
The team behind SPACE — the sandbox infra behind Perplexity's Computer — ran a CTF giving top models root in a VM with one goal: hack out. Key findings:
- No model escaped the VM, but gpt-56-sol, gpt-56-cyber, opus-5, and kimi-k3 (open weights) found and exploited a genuine vulnerability in network policy enforcement
- The root cause wasn't misconfiguration: CDNs and shared infra like Fastly and S3 serve many domains/buckets from shared IPs, so allowlisting pypi.org silently allowed other sites on those IPs; in one run gpt-56-cyber reached Taboola-related assets
- Several other sandbox providers — Daytona, Vercel, Modal, E2B — were similarly vulnerable and have been notified
A serious warning for agent sandbox isolation design.
More from coding & agent
- Two Codex agents coded, tested and submitted iOS & Android apps to stores in parallel — burkov · 2026-09-24
- You misunderstand AGENTS.md: how coding tools read project instructions — dotey · 2026-09-24
- Forced fresh-worker swap at 60k tokens: 10/12 Terminal-Bench tasks still pass — key_of_door · 2026-09-24
- Solo Dev Open-Sources Tapioca, a Go Terminal Coding Agent That Runs Fully Local — Practical_Witness_95 · 2026-09-24
- Anthropic launches Claude Marketplace with 2,000+ connectors and third-party agents — claudeai · 2026-09-24
- Nyx Terminal launches for Mac: a terminal built for running many coding agents at once — henrymodis · 2026-09-24