Security researchers have disclosed two vulnerabilities that escaped OpenAI Codex’s sandbox, including one that could turn the simple act of inspecting an untrusted repository into command execution on a developer’s computer.

Both flaws were reported to OpenAI on August 12 and fixed within eight days, according to researcher Oren Yomtov of Accomplish AI. The findings matter because coding agents routinely operate on third-party source code, making the sandbox a critical boundary between repository-controlled content and the developer’s wider system.

Heapjack crossed the strictest boundary

The more serious technique, named Heapjack, affected a Codex component called node_repl. Codex Desktop placed the component in a global configuration file, which meant Codex CLI users could inherit it without explicitly enabling it.

The design used trusted and untrusted JavaScript contexts in one Node.js process. A random token was intended to authorize requests from the trusted side, but both contexts shared the same memory heap. The untrusted context could take a V8 heap snapshot, identify token-shaped strings and test them until it found the valid credential.

With that token, an attacker could submit a request to Codex’s unsandboxed parent process. The proof of concept launched an application outside Codex’s process tree even while Codex was running in read-only mode. Researchers said access to Unix sockets, including a Docker daemon socket, could create additional impact.

A patching tool widened its own permissions

The second flaw, dubbed Overpatch, affected the open-source Codex CLI in workspace-write mode. Codex’s apply_patch tool derived write permissions from attacker-controlled path input. By including /tmp in a crafted patch, the technique widened access to the filesystem root, then followed a symbolic link to modify a shell startup file in the user’s home directory.

The two bugs share a broader lesson: a security control should not rely on secrets or permission decisions exposed inside the environment it is trying to constrain.

What users should do

  • Update Codex Desktop to build 26.818.21641 or later.
  • Update Codex CLI to 0.149.0 or later.
  • Treat unfamiliar repositories as hostile input, even when the agent is in a restricted mode.
  • Review whether coding agents can reach Docker sockets, credentials, shell startup files or other host-level control points.

OpenAI said it had addressed both issues and was strengthening controls on where agents can write files while expanding sandbox testing.

Sources

By Allan