Researchers escape OpenAI Codex sandbox to run commands on host
Accomplish AI researchers found two vulnerabilities in OpenAI Codex: Heapjack allows executing commands on the developer's machine from read-only mode without confirmation, and Overpatch bypasses write restrictions in Codex CLI. Both were reported to OpenAI on August 12 and fixed within eight days.
- Heapjack reads trust token from Node.js shared memory, runs commands outside sandbox
- Overpatch makes apply_patch write to home folder via symlink to .zshrc
- Fixes shipped in Codex Desktop 26.818.21641 and Codex CLI 0.149.0
- Vulnerabilities worked in strictest read-only mode without notifications
Read next
Security