Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » OpenAI Codex Sandbox Escape Let Attackers Run Commands in Read-Only Mode
    Technology

    OpenAI Codex Sandbox Escape Let Attackers Run Commands in Read-Only Mode

    Gary BehanBy Gary Behan29/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    OpenAI Codex sandbox escape
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    Two techniques for achieving an OpenAI Codex sandbox escape have been publicly detailed, one of them capable of running arbitrary commands on a developer’s machine from Codex’s most locked-down mode, with no prompt shown and nothing logged on screen. Both flaws were reported to OpenAI on 12 August and patched within eight days, according to Oren Yomtov of Accomplish AI.

    Accomplish published the technical details on 15 September, according to DevOps.com. The disclosure arrives at a moment when sandbox integrity in AI coding agents is drawing close scrutiny across the industry, and the specifics here are uncomfortable reading for anyone running Codex on a development machine.

    The Two Escapes, Explained

    The more serious of the pair, which Yomtov’s team calls Heapjack, targets a component named node_repl. Codex Desktop writes this component into the global ~/.codex/config.toml file at install time, with no opt-in and no setting to disable it. Because the entry lives in the shared config, plain Codex CLI users inherit the same tool without ever being asked. That detail matters: the attack surface is wider than the desktop application alone.

    node_repl runs a single Node.js process holding two separate JavaScript execution contexts, one trusted, containing OpenAI’s own code, and one untrusted, running the agent’s code. The trusted context proves itself by presenting a random token generated fresh on each run. The flaw is that both contexts share one memory heap, so that token is simply a string sitting in memory the untrusted side can reach. The untrusted code takes a heap snapshot with v8.getHeapSnapshot() and tries every UUID-shaped string it finds. A wrong guess returns “not authorised.” A correct token with a bad argument returns a real validation error, which confirms the token is right, a classic oracle.

    With the valid token in hand, the untrusted code writes its own request onto the pipe the trusted context uses to communicate with a native, unsandboxed parent process. The parent checks the token, finds it valid, and executes the request. The proof of concept used the system’s open command to launch an application outside Codex’s process tree entirely. The same access reaches any Unix socket (a Docker daemon socket being an obvious next target) and the tool for editing the global config file. All of this runs in read-only mode, the strictest sandbox setting, where the agent is not supposed to write anything at all.

    The second flaw, Overpatch, lives in the open-source Codex CLI. In workspace-write mode, the agent is meant to write only inside the project folder; a shell command aimed at the home directory is refused. The researchers found that Codex’s own patch tool, apply_patch, could be coaxed into writing there anyway. The tool grants write access to the parent folder of each path named in a patch. Name /tmp, and it effectively grants write access to the root of the disk.

    The working exploit chains two changes in a single patch: one naming /tmp to widen the permission, and one that appends a line to .zshrc via a symlink into the home directory. Remove the first change and the write is refused. Keep it, and the next terminal session the developer opens executes the attacker’s line, unsandboxed, without further interaction.

    OpenAI Codex Sandbox Escape: Why the Fix Matters

    Both bugs share the same structural shape: the enforcement mechanism was living inside the thing it was meant to enforce. apply_patch worked out its own permissions from attacker-supplied input. node_repl kept the secret separating trusted from untrusted code in the same memory as the untrusted code. In each case, the sandbox was told (from the inside) to let something through.

    The class of vulnerability is not new. In July 2026, Pillar Security researchers demonstrated the same principle across Cursor, Codex, Gemini CLI and Google’s Antigravity, where an agent that stays within its sandbox writes a file that a trusted tool outside the sandbox later runs. One commenter responding to Yomtov’s post on X put it plainly: “V8 contexts isolate globals, not memory, so the sandbox was really a promise the heap never agreed to.” Another described the trust boundary as “a room divider.” The default-enabled behaviour of node_repl drew separate criticism, with observers questioning why a privileged token was reachable from untrusted JavaScript at all.

    OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0, according to Accomplish. Users should update to those versions or later. Yomtov credited OpenAI with resolving both issues within eight days of his report.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleBragJack Browser Agent Attack Hijacks Five AI Assistants via One Rogue Extension
    Next Article Indexed-btree npm malware hid inside runtime calls to dodge install-script defences
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    EvilTokens PhaaS Takedown: Microsoft Seizes 50 Sites, Two Arrested in UK

    01/10/2026

    BigDiskBuster Windows Defender zero-day exploit freezes antivirus updates

    01/10/2026

    Zyxel GS1900 Switch Exploit Hits 996 Devices as CISA Orders Federal Patch

    01/10/2026

    BigCommerce Ribon app breach exposes shoppers at Master of Malt and beyond

    30/09/2026

    Microsoft 365 Companion Apps Retirement Set for 16 December

    30/09/2026

    Ireland’s DPC hits Google with €403m location data fine

    30/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.