Vulnerabilità · 160 giorni fa
Prompt injection can still break the trust boundary in agentic AI tools. In Google Antigravity, permitted file creation and native tool calls were enough to bypass Secure Mode and reach remote code execution, so the standard response of relying on sandboxing alone misses the real failure: the agent can be tricked into treating attacker-controlled content as instructions.
Pillar Security disclosed the flaw and Google has patched it. The issue affected Antigravity, Google’s AI-powered developer tool for filesystem operations, and it specifically defeated Secure Mode, which is meant to run commands in a virtual sandbox, throttle network access, and block writes outside the working directory.
The forward risk is that any agent platform that mixes file access, native tools, and prompt ingestion can turn untrusted content into code execution. Sandbox controls still matter, but they do not help if the agent itself can be induced to invoke privileged native functions before those controls apply.
4 fonti che coprono questa storia
Google Antigravity in Crosshairs of Security Researchers, Cybercriminals
Researchers discovered a remote code execution vulnerability and cybercriminals are using its reputation to deliver malware.
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
Antigravity Strict Mode bypass disclosed Jan 7, 2026, patched Feb 28, enables arbitrary code execution via fd -X flag.
Google Fixes Critical RCE Flaw in AI-Based 'Antigravity' Tool
The prompt-injection issue in the agentic AI product for filesystem operations was a sanitization issue that allowed for sandbox escape and code execution.
Google’s highest security setting for its agents runs command operations through a sandbox and throttles network access, but is still vulnerable to prompt injection.
Part of the PlainSec briefing for 2026-04-21