AgentsZed Editor Agent Sandbox Escapes CVE-2026-27976 CVE-2026-27967GitHub Advisory·high signalXBlueskyLinkedInCopy linkSymlink traversal sandbox escapes in Zed IDE agent features. First CVEs in a non-MS/Apple AI-native editor.SourceSource pageGitHub Advisory↳ Follow the threadStack layer / Threat patternZed v1.14.1-pre Sandboxes the Agent's Terminal and Fetch Tools and Adds a Reasoning-Effort SelectorZed GitHub ReleasesPolicy dependency / Stack layerQwen Scribe Brings Qwen3-ASR Dictation to Apple Silicon in 1.2 GB of RAMGitHub / Hacker NewsStack layer / Update threadPascal Editor Cuts Its First 1.0 Beta Today After Gaining 1,022 Stars in 24 HoursGitHubStack layer / Threat patternA Bug-Bounty Team With $1.5M in Payouts Open-Sources Its Internal Vulnerability-Hunting Orchestrator as open·krittGitHubThreat pattern / Update threadOpenAI Open-Sources Codex Security, the Tool Formerly Known Internally as Aardvark, Under Apache-2.0openai/codex-security (surfaced via Hacker News, 590 points / 225 comments; corroborated by The Decoder, Cybersecurity News)Stack layer / ContrastCindy Reaches 1,151 Stars in Eight Days by Letting One Task Switch Harnesses Mid-Flight — and Racks Up 329 Open Issues Doing ItGitHubStack layer / Threat patternA Reverse-Engineering Skill Router Hits 10,379 Stars by Gating Agents Behind Scope Authorization Before Any ActionGitHubPolicy dependency / Stack layerRefly Ships an Executable Skill Registry That Exports to Claude Code, Cursor, and Codex — or Deploys as an APIGitHub