Researchers escape OpenAI Codex sandbox to run commands on host
BLUF
OpenAI patched critical sandbox escapes in Codex that allowed host machine compromise.
NEWS
Researchers demonstrated two distinct methods to bypass OpenAI's Codex security sandbox, including one that executed commands on a developer's local machine from the most restricted mode. Both vulnerabilities have been identified and patched by OpenAI following responsible disclosure.
Why I Care
This highlights risks in AI-assisted coding tools where malicious prompts could lead to unauthorized system access. Developers and enterprises using Codex for sensitive codebases face potential data exfiltration or malware installation if unpatched versions were used.
Next Steps
Verify your Codex environment is updated to the latest version immediately. Review recent code generation logs for anomalies if you use unpatched instances.
Source: BleepingComputer ·