Researchers escape OpenAI Codex sandbox to run commands on host
Recorded: Sept. 20, 2026, 12:09 p.m.
| Original | Summarized |
Researchers escape OpenAI Codex sandbox to run commands on host News Featured OpenAI details more cases of AI agents taking unauthorized actions Brevo supply-chain attack injected ClickFix scripts on customer sites Cisco warns of max severity ISE zero-day exploited in attacks Microsoft shares workaround for Windows domain login issues Researchers escape OpenAI Codex sandbox to run commands on host BragJack attacks hijack AI browser agents through malicious extensions North Korean WaterPlum hackers infected 30,000 devices worldwide ShinyHunters hacks Clop leak site, threatens to extort ransomware gang Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityResearchers escape OpenAI Codex sandbox to run commands on host Researchers escape OpenAI Codex sandbox to run commands on host By Ax Sharma September 20, 2026 Security researchers found two ways out of the OpenAI Codex sandbox, one of them capable of running commands on a developer's machine from Codex's most locked-down mode, with no approval prompt and nothing shown on screen. The Heapjack attack path (Accomplish.ai) Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Codex Ax Sharma Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Cisco warns of max severity ISE zero-day exploited in attacks Microsoft shares workaround for Windows domain login issues Brevo supply-chain attack injected ClickFix scripts on customer sites Sponsor Posts Automate Onboarding and Access Reviews with No-Code IGA: See how it works Overdue a password health-check? Audit your Active Directory for free Patch automation needs more than speed. Action1 brings control into every stage of deployment. Watch a working exploit hit live controls and see exactly what blocks, detects, or misses Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Security researchers discovered two vulnerabilities allowing escape from the OpenAI Codex sandbox, enabling the execution of commands on the host machine from Codex's most restricted mode without requiring approval prompts or on-screen visibility. These flaws were reported to OpenAI and subsequently fixed within eight days, according to Oren Yomtov of Accomplish AI. The more severe vulnerability, termed Heapjack, allows a routine action to result in remote code execution. This attack path involves instructing Codex to open another repository, ask it a question about the code, and subsequently achieve unsandboxed command execution on the developer's computer. The Heapjack technique exploits a component named node_repl, which is integrated into Codex Desktop and configured in the global configuration file. This component runs two separate JavaScript execution contexts: one trusted, containing OpenAI's code, and one untrusted, running the agent's code. The vulnerability stems from both contexts residing within the same Node process and sharing a single memory heap. The trusted context verifies its status by presenting a random token, but the untrusted context can read this token directly from the shared memory. The attack proceeds by allowing the untrusted code to take a snapshot of the heap using v8.getHeapSnapshot() and test various strings shaped like a UUID. A correct token, when paired with a carefully crafted argument, results in a validation error that confirms the token is valid. Leveraging this valid token, the untrusted code can then write its request onto the same pipe used by the trusted context to communicate with an unsandboxed parent process. This allows the agent to execute system commands, such as using the open command to launch applications outside the sandbox process tree or accessing various Unix sockets like the Docker daemon socket, demonstrating control over the host system. The second vulnerability, Overpatch, exists within the open-source Codex command-line interface. In workspace-write mode, the agent was restricted to writing only within the project folder, and shell commands targeting the home directory were refused. Researchers successfully exploited this by utilizing Codex's own patch tool, apply_patch, to achieve write access beyond the intended boundaries. By providing input that named a path such as /tmp, the tool granted write access to the root of the disk. The working exploit involved chaining two changes: one that broadened permissions needlessly, and another that used a symbolic link to append content to the .zshrc file within the home directory. This exploit succeeded because the underlying enforcement mechanism was flawed; the patching tool granted permissions based on attacker-supplied input, effectively allowing the agent to bypass the sandbox constraints. Both vulnerabilities share a fundamental architectural flaw: the security enforcement mechanism was situated within the entity it was designed to protect. In Heapjack, the shared memory facilitated unauthorized leakage between trusted and untrusted code, and in Overpatch, the patching mechanism allowed permission grants based on external input. This pattern is not unprecedented; Pillar Security researchers previously demonstrated similar principles across other agents and tools like Cursor, Gemini CLI, and Google's Antigravity. Critics of the design suggested that the isolation was merely a promise because the heap mechanism failed to uphold the separation, leading to scrutiny regarding the reachability of privileged tokens from untrusted JavaScript. To mitigate these risks, OpenAI released updates, fixing Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0, advising users to adopt these updated versions. |