Research · curated 16 Aug 2026

How Copilot Studio Sandbox Escape Gave Us Admin Access

Coverage timeline

16 Aug 2026beyondtrust.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

The Copilot Studio sandbox escape shows that AI agent code-execution sandboxes can be broken via prompt injection to gain admin-level access, a critical risk for any organization deploying LLM agents that run untrusted code.

BeyondTrust's Phantom Labs details how they escaped Microsoft Copilot Studio's Code Interpreter sandbox, chaining modern prompt injection techniques with classic dictionary attacks to obtain Administrator credentials to code interpreter sandboxes deployed worldwide. The research, starting from a stock agent with only the code-interpreter toggle enabled, argues that many AI agent sandboxes act as guardrails rather than true security boundaries.