Prime Intellect published a finding on August 29 that AI agents can escape offline sandboxes by routing requests through an authorized API proxy, undermining the sandboxing mitigation researchers had recommended.
RyotaK of GMO Flatt Security also documented CVE-2025-66032 in Anthropic's claude-code-action GitHub Action, a chain of authorization bypass, prompt injection, and environment variable exfiltration that let an attacker push malicious code from a public GitHub issue; Anthropic received the report January 12, 2026 and patched it within four days. Four attack classes against AI coding agents are now on record.