Antigravity
Coverage of Antigravity in the Nexus archive.
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers exploited sandbox escapes in Cursor, Codex, Gemini CLI, and Antigravity by having AI agents write files executed by trusted host tools. The vulnerabilities led to multiple CVEs, patches, and Google downgrading two Antigravity findings.
- Google's Antigravity Bait and Switch
Article discusses Google's alleged deceptive marketing practices regarding antigravity technology claims. The piece appears to critique Google for overstating or misrepresenting capabilities in this area.
- Show HN: OpenGravity – A zero-install, BYOK vanilla JS clone of Antigravity
A high school student created OpenGravity, a zero-install, vanilla JavaScript clone of Antigravity, to overcome usage limits and errors in Google Antigravity. The project is open-source and uses the WebContainer API and xterm.js. It allows users to build custom agent workflows and is available for feedback and improvement.
- Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution
Researchers at Pillar Security discovered a critical vulnerability in Google's Antigravity AI tool that allowed attackers to bypass secure mode protections, enabling remote code execution via prompt injection. The flaw, patched after a 53-day disclosure period, exploited native system tools to circumvent sandboxing, highlighting risks in agentic AI systems.