Sandbox escape
Reaching outside the isolated environment something was supposed to be confined to.
A sandbox is a boundary, and boundaries have gaps: a mounted folder, an inherited environment variable, a network route that was left open because something needed it during setup.
For agent tooling the practical escape is usually not exotic. It is a directory somebody mounted read-write for convenience, or a credential inherited from the shell that started the container.
A sandbox you have not tested is an assumption, and every downstream permission decision was made on top of it.
Treating a container as a security boundary by default. It is one when it is configured to be, and the default configuration is convenience.
Related terms
See Sandbox escape on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue