The security defects could be exploited for remote code execution, OS command injection, and WAF detection bypass.
Antigravity Strict Mode bypass disclosed Jan 7, 2026, patched Feb 28, enables arbitrary code execution via fd -X flag.