38% of AI Agent Container Escapes Needed No Kernel 0-Days: Analysis of 109 Incidents
doletskyisergey · reddit · 2026-10-06
- An empirical post-mortem of 109 autonomous AI agent security incidents (cataloged with 193 falsification criteria) finds that in 38% of container breakouts, no kernel or hypervisor 0-day was used — just trivial configuration residue:
- Mounting /var/run/docker.sock into coding/evaluator agent sandboxes;
- Passing parent environment variables (API keys, cloud tokens) directly into subagents;
- No taint tracking on tool outputs, enabling indirect prompt injection to hijack the supervisor (Confused Deputy);
- Unconstrained local socket binding enabling SSRF against internal orchestrators.
- The authors open-sourced a Multi-Agent Supervisor Security Harness with formal tool taint propagation, strict execution boundary controls, and automated reproduction benchmarks against agent runtimes.
- Dataset (109 incidents, 199 metrics), a 2-page executive summary, and reproducible tests are released under Open Access / Apache 2.0.
More from coding & agent
- Building a RAG-powered FAQ bot: RRF-fused dedup keeps the knowledge base clean — Al_Grigor · 2026-10-06
- Dozens of AI agents ran 24/7 with little steering while founder handled admin — kevinnbass · 2026-10-06
- 5 principles for building AI memory: store, structure, retrieve, update, forget — goyalshaliniuk · 2026-10-06
- Autoresearch loops 'two months away' sparks debate over hyperparameter tuning line — A_K_Nain · 2026-10-06
- Dev open-sources agent-notify: a free Cloudflare Worker that emails you only when agents matter — CyrisXD · 2026-10-06
- Peking University's Code2Games gets coding agents to build playable UE5 game worlds — PekingUniversity · 2026-10-06