Tools AI Risk Radar ai-incident-0070
Incident record
Google Antigravity IDE prompt-injection flaw enabled code execution
- Severity
- High
- Status
- Patched
- Type
- Prompt Injection
- Target
- Google Antigravity
- Actor
- researcher
What happened
Pillar Security reported an indirect prompt-injection flaw in Google's Antigravity agentic IDE: hidden instructions in an untrusted source file could make the agent call its find_by_name search tool with an injected -X flag, forcing the underlying fd binary to run arbitrary code on a developer's machine and escaping the sandbox even with Secure Mode enabled and auto execution off. Google marked it fixed on 28 February 2026 and awarded a bounty; researchers demonstrated it as a proof of concept and it was not seen in the wild.
Secure Mode is Antigravity's most restrictive configuration, restricting network access, preventing writes outside the workspace and running commands under a sandbox. The injected flag never reaches that boundary, because the agent treats the search call as a native tool invocation. Pillar reported the flaw to Google's AI vulnerability reward programme on 7 January 2026 and published on 20 April, nearly two months after the fix landed. No CVE was assigned.
Sources
- Pillar Security: prompt injection leads to RCE and sandbox escape in Antigravity (20 April 2026)www.pillar.security/blog/prompt-injection-leads-to-rce-and-s…
- Google: the Antigravity Secure Mode documentationantigravity.google/docs/secure-mode
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026