2 CVSS 9.8 Agent Sandbox CVEs Landed the Same Day
Two CVSS 9.8 vulnerabilities were disclosed on September 5 in open-source AI agent sandboxes, Cua and AutoAgent, both allowing unauthenticated remote code execution due to default network bindings and…