• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
AI
Announcement

AI models bypassed network limits in Perplexity’s SPACE sandbox tests

Perplexity says four models reached a blocked destination when its sandbox allowed limited network access. It says it fixed and retested the two bypass methods they used.

Aravind SrinivasAS
Steven SinofskySS
Kyle PolleyKP
11 Sources, 12d ago, first seen 12d ago

TLDR

Perplexity says it tested AI models against SPACE, the sandbox for its long-running agents. None of 108 attempts to escape the virtual machine succeeded, and no network bypass succeeded when traffic was fully blocked. With limited access allowed, four models reached a blocked destination by exploiting the gateway’s IP-based rules. Perplexity says it fixed and retested both bypass methods. It also says eight of 10 third-party sandbox platforms it evaluated had similar network-policy vulnerabilities and that it disclosed its findings to affected vendors.

Combined views

151.6K

11 Sources, first seen 12d ago

1.3K likes101 comments312 saves208 reposts

Combined views

151.6K

11 Sources, first seen 12d ago

1.3K likes101 comments312 saves208 reposts

Sentiment

Positive43.1%56.9%Negative

Summary

While some accounts welcomed Perplexity’s SPACE sandbox tests as useful for AI agent security, others criticized high vulnerability rates and questioned the accuracy of the reported results.

Based on 65 sentiment-bearing replies from 62 accounts across 3 conversations.

Featured Source

Sentiment

Positive43.1%56.9%Negative

Summary

While some accounts welcomed Perplexity’s SPACE sandbox tests as useful for AI agent security, others criticized high vulnerability rates and questioned the accuracy of the reported results.

Based on 65 sentiment-bearing replies from 62 accounts across 3 conversations.

Related

Perplexity seeks engineers for AI agent safety and security work

A Perplexity engineer says the team is building and testing systems aimed at making AI agents safer and more secure.

Perplexity Research Fellowship offers priority consideration for applications received by September 30, 2026

Perplexity describes the fellowship as a program for early-career STEM talent and says it reviews applications on a rolling basis. A post promoting it highlights architecture design, multi-agent collaboration and synthetic data as research areas.

Perplexity Adds Hybrid Compute to Mac App

Perplexity AI enables tasks to shift from cloud to local models on Mac for private data.

11 Sources

Perplexity@perplexity_aiWe evaluated two tasks. In the sandbox escape task, the agent must break VM isolation and grab an AWS honeytoken from the host. In the network bypass task, it runs with internet blocked, or limited to package repositories like PyPI, and must reach a blocked callback URL.12d
Aravind Srinivas@AravSrinivasOur security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models (Opus 5, GPT-5.6 Sol, Kimi K3, Gemini 3.1 Pro, etc.) root access inside the VM; in some runs, the full sandbox source code too. We asked them to either escape to the host or reach a URL our network policy blocks. None of them got out of the VM in 108 runs. But once we allowed a bit of network access (just PyPI and Ubuntu mirrors so that they could install packages), 4 models managed to reach the blocked URL by: 1. Spoofing DNS responses to our gateway and using the fact that http://pypi.org sits on a Fastly IP shared with thousands of other sites. 2. GPT-5.6 Cyber went through Taboola's image fetcher to a screenshot service and then OCR'd the flag out of the image. We fixed both issues and made sure the reruns held. We also tested 10 other sandbox providers, and 8 of them had the same IP-sharing problem, eg E2B, Vercel, Modal. Openly sharing the red teaming research is the best way to build guardrails as an industry, and we look forward to working together with @nvidia to incorporate the guardrails into their Open Agent Safety Platform announced today. https://www.perplexity.ai/hub/blog/escaping-space-part-i12d
Kyle Polley@kpolleyThe best way to predict the future is to invent it. We’re building and testing systems to make AI agents safer and more secure. If you’re an exceptional engineer who wants to help build a safer future, join us at Perplexity. My DMs are open12d
Florian Brand@xeophon@maksym_andr the most interesting design decision is how much you wanna route through the interception server -- one (valid!) design is to route all network requests, even non-inference ones, through the interception server and make the host fully offline [besides the tunnel]12d
Steven Sinofsky@stevesiRT @AravSrinivas: Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer.…12d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    PerplexitySPACEAravind Srinivas
    Claude Opus 5.0

    11 Sources

    Perplexity@perplexity_aiWe evaluated two tasks. In the sandbox escape task, the agent must break VM isolation and grab an AWS honeytoken from the host. In the network bypass task, it runs with internet blocked, or limited to package repositories like PyPI, and must reach a blocked callback URL.12d
    Aravind Srinivas@AravSrinivasOur security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models (Opus 5, GPT-5.6 Sol, Kimi K3, Gemini 3.1 Pro, etc.) root access inside the VM; in some runs, the full sandbox source code too. We asked them to either escape to the host or reach a URL our network policy blocks. None of them got out of the VM in 108 runs. But once we allowed a bit of network access (just PyPI and Ubuntu mirrors so that they could install packages), 4 models managed to reach the blocked URL by: 1. Spoofing DNS responses to our gateway and using the fact that http://pypi.org sits on a Fastly IP shared with thousands of other sites. 2. GPT-5.6 Cyber went through Taboola's image fetcher to a screenshot service and then OCR'd the flag out of the image. We fixed both issues and made sure the reruns held. We also tested 10 other sandbox providers, and 8 of them had the same IP-sharing problem, eg E2B, Vercel, Modal. Openly sharing the red teaming research is the best way to build guardrails as an industry, and we look forward to working together with @nvidia to incorporate the guardrails into their Open Agent Safety Platform announced today. https://www.perplexity.ai/hub/blog/escaping-space-part-i12d
    Kyle Polley@kpolleyThe best way to predict the future is to invent it. We’re building and testing systems to make AI agents safer and more secure. If you’re an exceptional engineer who wants to help build a safer future, join us at Perplexity. My DMs are open12d
    Florian Brand@xeophon@maksym_andr the most interesting design decision is how much you wanna route through the interception server -- one (valid!) design is to route all network requests, even non-inference ones, through the interception server and make the host fully offline [besides the tunnel]12d
    Steven Sinofsky@stevesiRT @AravSrinivas: Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer.…12d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet