chiprook
← Security
SecurityOctober 4, 2026, 08:38

Codex sandbox escape: token in shared heap and apply_patch grant on /tmp

Two Codex flaws were disclosed: in read-only mode untrusted code could recover a trust token from the shared Node heap and run commands on macOS, while workspace-write apply_patch granted write access to the parent folder of any path. Both were reported to OpenAI on August 12 and fixed within eight days in CLI 0.149.0 and Desktop 26.818.21641.

Codex sandbox escape: token in shared heap and apply_patch grant on /tmp
#OpenAI#Codex
Read next
Security

Researchers escape OpenAI Codex sandbox to run commands on host

Security

Expert blasts OpenAI security after another agent escape from sandbox

AI

Simon Willison's 2026 LLM timeline: agent breakouts, sandbox escapes and felony cyberattacks

Security

Semicolon in a Codex branch name leaked GitHub token via command injection