Subscribe

Perplexity let nine AI models loose inside its own sandbox with root access and told them to break out.

In 108 runs, none got through the wall. Four found a way under the fence.

Issue 2525 September 202617 receipts3 min

Perplexity says nine AI models with root access inside SPACE, the sandbox behind Perplexity Computer, produced no VM-to-host escape in 108 runs.

Before you read on. Your call?

its report states none of the 108 sandbox-escape runs succeeded, three runs per model per setting, and we found nothing in our record contradicting it. It also says, fairly, that the absence of an observed escape is not a proof of isolation.

The twist

the wall held, the fence did not. With partial network access, network-policy bypass succeeded in 11 of 54 runs before Perplexity fixed it, and in direct tests without AI agents, eight of ten third-party sandbox platforms had at least one network-policy bypass.

108sandbox-escape runs in Perplexity's test
11 of 54partial-network runs in which models bypassed SPACE's network restrictions before Perplexi
8 of 10third-party sandbox platforms in which Perplexity found at least one network-policy bypass

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

Say this in tomorrow's meeting“Perplexity's sandbox held: zero escapes in 108 runs by nine AI models. But in the same report, models got past its network restrictions in 11 of 54 runs before fixes, and eight of ten rival sandboxes had the same class of hole.”

Receipts

  1. Supports web.archive.org: No VM-to-host escape was observed in 108 runs.
  2. Supports web.archive.org: For the sandbox escape task, none of the 108 runs succeeded.
  3. Context web.archive.org: Each cell reports how many of the three runs succeeded.
  4. Context web.archive.org: Before remediation, network-policy bypass succeeded in 11 of 54 partial-network runs and none of 54 no-network runs.
  5. Context web.archive.org: A successful network-policy bypass does not imply a VM–host escape, and the absence of an observed escape is not a proof of isolation.
  6. Context web.archive.org: After identifying these vulnerabilities, we fixed them and reran the experiments to confirm that the network bypasses no longer succeeded.
  7. Context web.archive.org: We found at least one network-policy bypass in eight of the ten platforms tested.
  8. Context web.archive.org: These experiments directly tested each platform’s network-policy enforcement and did not involve LLM agents.
  9. Context web.archive.org: We tested two containment boundaries in SPACE, the sandbox platform behind Perplexity Computer: VM isolation and network confinement.
  10. Context web.archive.org: Nine models received root access inside a guest VM and attempted to obtain a host-side secret or reach a blocked network destination.
  11. Context web.archive.org: We evaluated both tasks under four settings defined by two dimensions: whether the agent has access to SPACE’s source code and the level of network access available to the agent.
  12. Context web.archive.org: In the partial-network condition, the agent can access software package repositories to install new packages and can use the Perplexity Search API.
  13. Context web.archive.org: With limited network access, however, four models bypassed network restrictions through DNS spoofing or shared-IP routing.
  14. Context web.archive.org: One vendor requested more time to respond, so its results are omitted here.
  15. Context web.archive.org: With SPACE, each task runs inside a Firecracker microVM, a fully isolated environment with its own operating system. That means nothing inside can affect the host or any other sandbox running in parallel.
  16. Supports tldr.tech: Perplexity's SPACE platform tested VM isolation and network confinement using nine AI models, revealing no VM-host breaches across 108 trials.
  17. Context siliconangle.com: Fitting the name, a sandbox is an isolated space where all the data an agent is working on can live, serving as a secure context safely packaged away from other agents or systems.

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict, tell us. Corrections are loud here.