The information about the vulnerabilities is relayed by DevOps.com.

Codex fixed Heapjack and Overpatch, two vulnerabilities that allowed an escape from the sandbox without an approval prompt. DevOps.com reported that Accomplish researchers disclosed the vulnerabilities.

According to DevOps.com, Heapjack allowed commands to run outside the sandbox even in read-only mode. Overpatch allowed files to be written outside the workspace.

The fixes are in Codex CLI 0.149.0 and Codex Desktop build 26.818.21641.

Claim check:

  • DevOps.com reported that Accomplish researchers disclosed two Codex vulnerabilities, Heapjack and Overpatch, which allowed an escape from the sandbox without an approval prompt. (confirmed only by the carrying publication: evidence; «Researchers at Accomplish disclosed Heapjack and Overpatch, two vulnerabilities that enabled OpenAI Codex to escape its sandbox without an approval prompt.»)
  • According to the publication, Heapjack allowed commands to run outside the sandbox even in read-only mode, while Overpatch allowed files to be written outside the workspace. (confirmed only by the carrying publication: evidence; «Heapjack could achieve unsandboxed command execution even from Codex’s read-only mode by extracting a trust token from a shared V8 heap. - Overpatch abused apply_patch permissions to write outside the workspace and could modify files such as .zshrc.»)
  • DevOps.com stated that the fixes are in Codex CLI 0.149.0 and Codex Desktop build 26.818.21641. (confirmed only by the carrying publication: evidence; «The fixes are in Codex CLI 0.149.0 and Codex Desktop build 26.818.21641.»)

Publications:

score 80.2 out of 100 · kind: incident