AgentsCVE-2026-27952 Agenta-API Sandbox Escape via NumPyTheHackerWire·high signalXBlueskyLinkedInCopy linkSandbox escape in Agenta-API via incorrectly allowlisted numpy. Same dangerous allowlist pattern as n8n and Langflow.SourceSource pageTheHackerWire↳ Follow the threadPolicy dependency / Stack layerFour advisories land on Databricks' Omnigent meta-harness, one critical, all reported by an autonomous security agentGitHub Security AdvisoriesPolicy dependency / Stack layerCROSS-CATEGORY: Four Unrelated Vendors Shipped Agent Authorization Control Planes Inside 48 HoursJetStream (corroborated by Genesys Xperience 2026 coverage, aiagentstore.ai and Hacker News Show HN)Policy dependency / Stack layerPattern: four coding-agent CLIs shipped self-hosted or in-network execution controls in the same weekCursorPolicy dependency / Stack layerUnsloth 0.1.805-beta doubles Qwen3.8-Flash-Next and GLM-5.3-Flash inference with MTP on by defaultGitHubStack layer / Update threadQwen Code 0.23.0 adds scoped workspace memory with enforced filesystem boundaries and cross-session agent messagingGitHubStack layer / Update threadClaude Code adds a Containment Escape rule to auto mode and blocks plugin symlink path escapesGitHub (anthropics/claude-code)Stack layer / Update threadMagnitude shipped three CLI releases in 44 hours for a local inference server that swaps your agent off the APIGitHub TrendingStack layer / Update threadPageIndex 0.2.14 makes the local and cloud clients one surface and exports its tools straight into OpenAI, Anthropic and Claude agentsGitHub