One argument-injection bug took down OpenAI Codex at Pwn2Own
Day one of Pwn2Own Ireland 2026 saw 32 zero-days and over $388,000 in payouts. Targets included OpenAI's cloud coding agent Codex, LiteLLM and an AI database product; Codex fell to a single argument-injection flaw in its tool-call path.
- 32 zero-days on day one of Pwn2Own Ireland 2026, over $388,000 awarded
- OpenAI Codex compromised by a single argument-injection bug
- LiteLLM and an AI database product also hit the same day
- Attack targets the tool-call handoff, not the model's prompt
Read next
Security