Post-Cutoff.com
  1. Home
  2. Posts
  3. Aravind Srinivas

Aravind Srinivas

Aravind Srinivas @AravSrinivas · x · 2026-09-28 · ★★★ · archived

Open the original ↗

Cited as a source by: 2026-09-28-nvidia-open-agent-safety-platform

Summary

Archived text

Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models (Opus 5, GPT-5.6 Sol, Kimi K3, Gemini 3.1 Pro, etc.) root access inside the VM; in some runs, the full sandbox source code too. We asked them to either escape to the host or reach a URL our network policy blocks.

None of them got out of the VM in 108 runs.

But once we allowed a bit of network access (just PyPI and Ubuntu mirrors so that they could install packages), 4 models managed to reach the blocked URL by:

  1. Spoofing DNS responses to our gateway and using the fact that http://pypi.org sits on a Fastly IP shared with thousands of other sites.
  2. GPT-5.6 Cyber went through Taboola's image fetcher to a screenshot service and then OCR'd the flag out of the image.

We fixed both issues and made sure the reruns held. We also tested 10 other sandbox providers, and 8 of them had the same IP-sharing problem, eg E2B, Vercel, Modal.

Openly sharing the red teaming research is the best way to build guardrails as an industry, and we look forward to working together with @nvidia to incorporate the guardrails into their Open Agent Safety Platform announced today.

https://www.perplexity.ai/hub/blog/escaping-space-part-i

Quoting @perplexity_ai: We’re partnering with Nvidia and 100+ industry partners to build infrastructure that contains rogue AI agents.

In this research, we gave 9 AI models root access inside SPACE and told them to break out.

Across 108 runs, none breached the VM boundary. https://www.perplexity.ai/hub/blog/escaping-space-part-i

views 96098 · likes 1174 · reposts 142 · replies 94 (at fetch time)

Archived 2026-09-29 via fxtwitter (unofficial).

Archived text

Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models (Opus 5, GPT-5.6 Sol, Kimi K3, Gemini 3.1 Pro, etc.) root access inside the VM; in some runs, the full sandbox source code too. We asked them to either escape to the host or reach a URL our network policy blocks.

None of them got out of the VM in 108 runs.

But once we allowed a bit of network access (just PyPI and Ubuntu mirrors so that they could install packages), 4 models managed to reach the blocked URL by:

  1. Spoofing DNS responses to our gateway and using the fact that http://pypi.org sits on a Fastly IP shared with thousands of other sites.
  2. GPT-5.6 Cyber went through Taboola's image fetcher to a screenshot service and then OCR'd the flag out of the image.

We fixed both issues and made sure the reruns held. We also tested 10 other sandbox providers, and 8 of them had the same IP-sharing problem, eg E2B, Vercel, Modal.

Openly sharing the red teaming research is the best way to build guardrails as an industry, and we look forward to working together with @nvidia to incorporate the guardrails into their Open Agent Safety Platform announced today.

https://www.perplexity.ai/hub/blog/escaping-space-part-i

Quoting @perplexity_ai: We’re partnering with Nvidia and 100+ industry partners to build infrastructure that contains rogue AI agents.

In this research, we gave 9 AI models root access inside SPACE and told them to break out.

Across 108 runs, none breached the VM boundary. https://www.perplexity.ai/hub/blog/escaping-space-part-i

views 96098 · likes 1174 · reposts 142 · replies 94 (at fetch time)

Archived 2026-09-29 via fxtwitter (unofficial).

Related events

All posts · id: x-aravsrinivas-2104597362475708781