Hacker News
Wiz Discloses CosmosEscape — a Gremlin Sandbox Break That Exposed the Azure Cosmos DB Master Key, Found With an Early Version of Its AI Vulnerability Researcher
Disclosed July 30, CosmosEscape chained .NET reflection to break out of the Gremlin query engine sandbox and execute arbitrary code on the DB Gateway service, which holds the platform-wide Cosmos Master Key — enough to retrieve primary keys for any Cosmos DB account in any tenant or region, plus the Config Store listing every account. Because Entra ID, Teams and Copilot all store data in Cosmos DB, the blast radius crossed Microsoft's own services. Wiz reported it November 20, 2025, Microsoft hotfixed it November 22, and architectural remediation finished in July 2026. Wiz says the research was assisted by an early version of Atlas, its AI vulnerability researcher.
↳ Follow the thread