AgentsThree Independent Sandbox Escape Disclosures in One WeekSnyk Labs·high signalXBlueskyLinkedInCopy linkOpenClaw TOCTOU (Snyk), Zed symlink traversal CVE-2026-27976, Claude Code denylist bypass (Ona). Confirms path-based containment is systemically broken.SourceSource pageSnyk Labs↳ Follow the threadPolicy dependency / Stack layerCherry Studio v2.0.9 unifies tool approval into one declarative policy and lets the provider catalog hot-update without an app releaseGitHubStack layer / Threat patternClaude Code ships /claude-api cost-optimize, a skill that profiles an existing project's API spend one measured change at a timeClaude Code changelogPolicy dependency / Stack layerLMSM Ports the Linux Security Modules Split to LLM Serving, Cutting HarmBench ASR 39.20% to 3.32% at 98.14% ThroughputarXiv 2608.25697Policy dependency / Stack layerOmniRoute broke a 27-day release silence with v3.8.50 on August 26 and maintains a rolling provider-catalog export tagGitHubPolicy dependency / Stack layerPeakBench separates an agent's dependency planning from its resource scheduling, and finds good planning does not produce safe parallel executionarXivPolicy dependency / Stack layerBayesian self-escalation lets an agent hand off mid-reasoning, beating post-hoc routing at equal costarXivStack layer / Threat patternHolmesGPT 0.40.0 is almost entirely a security release: command injection across five toolsets, SSRF, and signed bash approval prefixesGitHubStack layer / Threat patternbrowser-use/browser-harness v0.1.10 is a pure agent-security release: CDP credentials redacted from logs and orchestrator daemons now fail closedGitHub