

GitLab's Threat Research Group found a critical sandbox escape in vm2 that runs attacker code using the library's own documented configuration.

GitLab's Threat Research Group found a critical template injection in Serena that runs attacker code the moment a developer opens a repository.

Stuck in an evaluation with no way out, an AI agent escaped in an hour through the one service on its allowlist. Here's the gap that opened.
All fields required