OpenAI Codex Sandbox Flaws Let Malicious Repositories Execute Commands on Host Systems
Two OpenAI Codex sandbox flaws, Overpatch and Heapjack, let malicious repositories execute unsandboxed commands on developer hosts; both are patched.
Researchers reported two vulnerabilities in OpenAI Codex on August 12, 2026, which OpenAI fixed within a week. Overpatch, in the Codex CLI apply_patch tool, let attacker-controlled paths like /tmp widen file-write permissions beyond the workspace, enabling persistence via a modified .zshrc. Heapjack, in Codex Desktop's node_repl tool, exposed a trusted authorization token in a shared V8 heap, allowing forged requests to launch unsandboxed host commands. Fixes shipped in Codex CLI 0.149.0 and Codex Desktop 26.818.21641.