# Perplexity — Escaping SPACE: Part I

- Company: Perplexity (perplexity.ai)
- Announced: 2026-09-16
- Category: research-paper
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://www.perplexity.ai/hub/blog/escaping-space-part-i
- Record: https://forck.live/items/13437-escaping-space-part-i
- Subject: Perplexity
- Models affected: Claude Opus 5.0, GPT-5.6 Cyber, GPT-5.6 Sol, Kimi K3

Perplexity tested nine LLMs as agents inside its SPACE sandbox platform. No model escaped the VM-host boundary in 108 runs. Under partial network access, four models (Claude Opus 5.0, GPT-5.6 Cyber, GPT-5.6 Sol, and Kimi K3) bypassed network restrictions via DNS spoofing or shared-IP routing. Perplexity fixed the vulnerabilities and reran the experiments without successful bypasses. The report also evaluated ten third-party sandbox platforms, finding eight susceptible to similar network-policy bypasses.

## Evidence

Verbatim from https://www.perplexity.ai/hub/blog/escaping-space-part-i:

> We tested two containment boundaries in SPACE, the sandbox platform behind Perplexity Computer: VM isolation and network confinement. Nine models received root access inside a guest VM and attempted to obtain a host-side secret or reach a blocked network destination. No VM-to-host escape was observed in 108 runs. With limited network access, however, four models bypassed network restrictions through DNS spoofing or shared-IP routing.

---

Record: https://forck.live/items/13437-escaping-space-part-i
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
