Find notable cyber news and cases, enriched with sources, timelines, and signals.

OpenAI Codex sandbox escape fixes in Desktop and CLI

Security Tool/Service
First reported
Last updated
Happening score
H score 11
1 unique sources, 1 articles

Summary

Hide ▲

OpenAI fixed Heapjack in Codex Desktop and Overpatch in Codex CLI, closing sandbox escapes that could let untrusted agent activity reach a developer's host. The flaws broke command-execution boundaries in OpenAI Codex, including a path to unsandboxed command execution from read-only mode. Researchers reported both issues on August 12, and OpenAI patched them within eight days. Users should upgrade to Codex Desktop build 26.818.21641 or Codex CLI 0.149.0 or later.

Related Happenings

Claude Opus 5 Helped Hacktron Chain Discourse libheif RCE into OpenAI Staff Account Access remote code execution flaw (CVE-2026-32882)

Vulnerability
H score39 First: 18.09.2026 15:45 Last: 18.09.2026 15:45 Sources 1

About this happening: Discourse HEIC/HEIF upload processing is tied to CVE-2026-32882, a flaw that Discourse rates as remote code execution with an 8.8/10 severity score. The issue sits...

OpenAI hit by account takeover attack

Incident
H score18 First: 18.09.2026 15:45 Last: 18.09.2026 15:45 Sources 1

About this happening: OpenAI suffered an employee account takeover that led to internal repository access and limited reads of private-repository metadata and commits. The access path ran t...

AI coding agents plugin pinning bypass security flaw

Vulnerability
H score60 First: 18.09.2026 14:01 Last: 18.09.2026 14:01 Sources 1

About this happening: Plugin pinning bypass in four AI coding agents lets a repository owner swap a supposedly reviewed plugin for malicious code, turning a trusted add-on into a code-execu...

OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)

Vulnerability
H score17 First: 02.09.2026 17:06 Last: 02.09.2026 17:06 Sources 1

About this happening: OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A mal...

OpenAI Artifactory service unavailable after sustained agent activity

Service Disruption
H score29 First: 27.08.2026 21:36 Last: 27.08.2026 21:36 Sources 1

About this happening: OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outag...

Timeline

  1. 20.09.2026 15:00 2 articles · 1h ago

    Researchers disclose Heapjack and Overpatch in OpenAI Codex

    Initial Disclosure

    Researchers disclosed two OpenAI Codex sandbox escapes to OpenAI on August 12, 2026: Heapjack could run commands on a developer's machine from Codex's read-only mode, and Overpatch let Codex CLI's apply_patch write outside the workspace through a symlink and permission flaw.

    Show sources
  2. 20.09.2026 15:00 1 articles · 1h ago

    OpenAI ships Codex Desktop 26.818.21641 and Codex CLI 0.149.0 fixes

    Mitigation Patch Update

    OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0, and users were told to update to those versions or later.

    Show sources