www.accomplish.ai Critical Vulnerabilities Found in OpenAI Codex Sandbox
Article Content
- •Heapjack allows remote code execution via a shared memory heap in Codex Desktop.
- •Overpatch enables unauthorized disk access through the Codex CLI patch tool.
- •Both vulnerabilities were reported on August 12, 2026, and fixed within eight days.
Security researchers discovered two significant vulnerabilities in the OpenAI Codex sandbox, reported on August 12, 2026, and patched within eight days. The first vulnerability, named Heapjack, allows remote code execution by exploiting a shared memory heap in the Codex Desktop application, enabling untrusted code to access trusted context tokens. The second vulnerability, Overpatch, affects the open-source Codex CLI, allowing unauthorized write access to the entire disk through a patch tool. These vulnerabilities could potentially compromise developer machines and systems running Codex. Both flaws were addressed by OpenAI shortly after being reported. The Codex tool is widely used for coding assistance, making these vulnerabilities particularly concerning for developers. The researchers emphasized the lack of opt-in mechanisms for security features in Codex. The vulnerabilities highlight the importance of rigorous security practices in AI development tools.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track OpenAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…