Codex sandbox escape: token in shared heap and apply_patch grant on /tmp
Two Codex flaws were disclosed: in read-only mode untrusted code could recover a trust token from the shared Node heap and run commands on macOS, while workspace-write apply_patch granted write access to the parent folder of any path. Both were reported to OpenAI on August 12 and fixed within eight days in CLI 0.149.0 and Desktop 26.818.21641.
- Heapjack: the trust token sat in the same V8 heap as untrusted code
- Error messages acted as an oracle, leaking whether a token guess was close
- Overpatch: apply_patch granted write access to the parent of each path
- Fixes shipped in CLI 0.149.0 and Desktop 26.818.21641 within eight days
Read next
Security