chiprook
← Security
SecurityOctober 8, 2026, 19:32

One argument-injection bug took down OpenAI Codex at Pwn2Own

Day one of Pwn2Own Ireland 2026 saw 32 zero-days and over $388,000 in payouts. Targets included OpenAI's cloud coding agent Codex, LiteLLM and an AI database product; Codex fell to a single argument-injection flaw in its tool-call path.

One argument-injection bug took down OpenAI Codex at Pwn2Own
#OpenAI#Codex#LiteLLM#Pwn2Own
Read next
Security

Pwn2Own Ireland: 32 zero-days and $388,500 on day one

Security

LiteLLM auth bypass: a one-character token unlocked MCP tools

Security

Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers

AI

OpenAI speeds up GPT-6 Astra and GPT-6.1 Sol by 50% on day one of 28-day Codex sprint