Researchers escape OpenAI Codex sandbox to run commands on host
Executive Summary
Researchers discovered two methods to escape the OpenAI Codex sandbox, enabling execution of arbitrary commands on a developer’s machine even from the platform’s most restricted mode. The exploits allowed direct host access, posing a significant security risk. OpenAI has since patched both vulnerabilities, restoring sandbox isolation.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-20T12:00:00+00:00 - Category: threat-intel
Original Description: Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]
"If we are facing in the right direction, all we have to do is keep on walking."
— Unknown
Source: Bleeping Computer