{"data":{"id":"ab4a38e5-af08-4c1d-a038-1081186a264a","title":"Researchers escape OpenAI Codex sandbox to run commands on host","summary":"Security researchers discovered two sandbox escape vulnerabilities in OpenAI Codex, a coding assistant tool that runs code in a restricted environment (sandbox, a confined area where untrusted code cannot access the wider system). The more critical flaw, called Heapjack, allows an attacker to execute commands on a developer's computer without permission by reading a security token from shared memory and impersonating the trusted system. Both vulnerabilities were reported to OpenAI on August 12 and fixed within eight days.","solution":"Both flaws were fixed within eight days of being reported to OpenAI on August 12, according to Oren Yomtov of Accomplish AI. The source does not specify which version numbers contain the fixes or provide details about the specific patches applied.","labels":["security"],"sourceUrl":"https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/","publishedAt":"2026-09-20T12:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI Codex","Cursor","Gemini CLI","Google Antigravity"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-20T12:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}