YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0070

Incident record

Google Antigravity IDE prompt-injection flaw enabled code execution

Severity
High
Status
Patched
Type
Prompt Injection
Target
Google Antigravity
Actor
researcher

What happened

Pillar Security reported an indirect prompt-injection flaw in Google's Antigravity agentic IDE: hidden instructions in an untrusted source file could make the agent call its find_by_name search tool with an injected -X flag, forcing the underlying fd binary to run arbitrary code on a developer's machine and escaping the sandbox even with Secure Mode enabled and auto execution off. Google marked it fixed on 28 February 2026 and awarded a bounty; researchers demonstrated it as a proof of concept and it was not seen in the wild.

Secure Mode is Antigravity's most restrictive configuration, restricting network access, preventing writes outside the workspace and running commands under a sandbox. The injected flag never reaches that boundary, because the agent treats the search call as a native tool invocation. Pillar reported the flaw to Google's AI vulnerability reward programme on 7 January 2026 and published on 20 April, nearly two months after the fix landed. No CVE was assigned.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026