Google AI Development Tool Antigravity Flaw Allows Sandbox Bypass and Remote Command Execution
Google Antigravity is an AI agent development tool that can independently search files, interact with its environment and execute tasks. Because agents of this kind have elevated system privileges, security modes and sandboxing are intended to isolate risks. A prompt-injection vulnerability disclosed by Pillar Security showed that malicious content could still induce an agent to breach those defenses, putting developers’ devices and code at risk.
Pillar Security researchers found that attackers could exploit a validation flaw in Antigravity’s file-search tool to bypass the security mode’s sandbox protections and remotely execute malicious commands. Google patched the flaw by the end of February, but had not issued a formal security advisory or assigned a CVE number when the vulnerability was disclosed. Reports also did not identify the affected versions, any known attacks or financial losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventGoogle Pulls ADK Workflows Over Agent-to-Agent Flaw
Google’s Agent Development Kit (ADK) helps developers build and orchestrate AI agents, including systems in which one agent delegates work to another. That architecture creates a new security boundary: a low-privilege agent that processes untrusted text may indirectly command a more powerful agent. Pillar Security said its research exposed a first-of-its-kind agent-to-agent privilege-escalation path in Google’s ADK Python repository automation, highlighting why enterprises must model agent identities, credentials and delegation chains as part of their cybersecurity controls.
On Aug. 3, 2026, Pillar researcher Dan Lisichkin disclosed that a malicious public GitHub issue could prompt-inject the issue-analysis agent into posting /adk-issue-fix as the trusted adk-bot account, activating a privileged workflow. The proof of concept achieved code execution on a CI runner and exposed a bot personal access token, a Google API key and a Google Cloud service-account credential; no in-the-wild exploitation or financial loss was reported. Google removed issue-analyze.yml, issue-fix.yml and pr-analyze.yml in a patch carrying a June 9 author date, and confirmed the issue fixed on July 21.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →