OpenAI Codex recently faced two significant security vulnerabilities that allowed malicious repositories to potentially execute commands on a developer’s local system. These vulnerabilities, identified as Overpatch and Heapjack, were reported to OpenAI on August 12, 2026, and were addressed in under a week. The more critical issue, Heapjack, emerged when a developer accessed an attacker-controlled repository in Codex and queried the agent about its contents. This flaw could lead to command execution without any approval prompts or warnings, even when Codex was functioning in its strict read-only sandbox mode. Overpatch was identified within the open-source Codex CLI and its apply_patch editing tool. In an ideal scenario,...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!