bleeping-computer · Crawled Sep 20, 2026
Researchers escape OpenAI Codex sandbox to run commands on host
Read original article ↗AI Summary
Security researchers discovered two sandbox escape vulnerabilities in OpenAI's Codex that allowed untrusted code to execute commands on the host system. The more severe, named Heapjack, exploited shared memory in a Node.js process to steal a UUID token and gain unauthorized access to a privileged parent process, enabling remote code execution without user interaction. The second flaw, Overpatch, abused a patch utility in Codex CLI to escalate file write permissions and modify files outside the intended directory via symlink manipulation. Both vulnerabilities were fixed by OpenAI within eight days of disclosure.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.