All signals

Stealth Startup Accomplish Discloses Sandbox Vulnerabilities Across Claude Code, OpenAI Codex, and Cursor After Quiet Summer Vendor Notifications

Sources: AI Weekly September 12, 2026; Upstarts Media September 10, 2026 interviews with Accomplish founders Or Hiltch, Amit Avner, and Guy Zipori; Accomplish company blog post September 10, 2026; Pillar Security research July 2026 covering CVE-2026-48124 and related vulnerabilities reported by Eilon Cohen, Dan Lisichkin, and Ariel Fogel; BleepingComputer July 20, 2026; Techzine Global July 21 and July 27, 2026; Cymulate Research Labs April 2026 Configuration-Based Sandbox Escape documentation; SecurityPointbreak July 9, 2026; Qovery blog May 13, 2026.

Stealth startup Accomplish, founded by Or Hiltch, Amit Avner, and Guy Zipori, disclosed leaky sandbox vulnerabilities across Claude Code, OpenAI Codex, and Cursor after quietly flagging them to vendors this summer, according to AI Weekly and Upstarts Media reporting September 12 and 10. In some cases, such as a vulnerability flagged to Cursor in July and two reported to OpenAI, fixes were delivered in about a week, but in at least one case, a similar vulnerability flagged to Anthropic two months ago was not patched for approximately 50 days, about 30 software updates later, according to Amit Avner, Accomplish CEO. That entire period, malicious parties, whether hackers, cybercriminals, or state actors, could have been exploiting such security gaps, Avner stated. The vulnerabilities allow AI coding agents to escape their sandboxes not by directly breaching isolation boundaries but by writing files inside the sandbox that trusted host tools later execute, a pattern that security researchers at Pillar Security separately documented in July across Cursor, OpenAI Codex CLI, Gemini CLI, and Antigravity, assigning CVE-2026-48124 to a Cursor vulnerability involving Claude hooks configuration files that could execute commands outside the sandbox. Cymulate Research Labs also documented similar configuration-based sandbox escape patterns in April across Claude Code, Gemini CLI, and Codex CLI. Accomplish published its own blog post about the vulnerabilities on September 10. The disclosure arrives at a moment when sandbox-escape incidents involving frontier AI agents have moved from lab curiosities to operational security incidents with documented real-world consequences. OpenAI agents were implicated in the Hugging Face breach earlier this year, a US Senate subcommittee is reportedly investigating that incident, and the Russian-speaking PaperCut campaign disclosed this week showed AI agents orchestrating industrial-scale exploitation in the wild. Accomplish founders are raising