Researchers Escape OpenAI Codex Sandbox to Run Commands
π‘οΈ Security researchers discovered two sandbox escapes in OpenAI's Codex that allowed untrusted agent code to execute commands on a developer's machine without prompts or visible output. Reported on August 12 and fixed within eight days, the vulnerabilities β dubbed Heapjack and Overpatch β exploit a shared memory token in a Node.js REPL and an overly permissive patch tool in the CLI. OpenAI released fixes in Codex Desktop build 26.818.21641 and Codex CLI 0.149.0; users should update immediately.