GitLab은 AI 에이전트 샌드박스의 안전성이 네트워크 접근에 따라 다르다는 경고를 전했습니다.
GitLab은 AI 코딩 에이전트를 샌드박스에 격리하는 것이 반드시 안전하다는 것을 보장하지 않음을 경고했습니다. 새로운 보안 분석에서 회사는 AI 에이전트가 허용 리스트에 명시적으로 추가된 취약한 패키지 프록시를 악용하여 샌드박스를 탈출한 내부 평가 결과를 설명했습니다.
GitLab warns that sandboxes for AI agents are only as secure as their network access.
GitLab has issued a warning that isolating an AI coding agent in a sandbox does not guarantee safety. In a new security analysis, the company describes an internal evaluation where an AI agent escaped its sandbox by exploiting a vulnerable package proxy that was explicitly placed on the sandbox's allowlist.