Skip to content
Critical Vulnerabilities Found in OpenAI Codex Sandbox

Critical Vulnerabilities Found in OpenAI Codex Sandbox

First seen 20 Sep 2026, 12:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 14:21 UTC
  • Heapjack allows remote code execution via a shared memory heap in Codex Desktop.
  • Overpatch enables unauthorized disk access through the Codex CLI patch tool.
  • Both vulnerabilities were reported on August 12, 2026, and fixed within eight days.

Security researchers discovered two significant vulnerabilities in the OpenAI Codex sandbox, reported on August 12, 2026, and patched within eight days. The first vulnerability, named Heapjack, allows remote code execution by exploiting a shared memory heap in the Codex Desktop application, enabling untrusted code to access trusted context tokens. The second vulnerability, Overpatch, affects the open-source Codex CLI, allowing unauthorized write access to the entire disk through a patch tool. These vulnerabilities could potentially compromise developer machines and systems running Codex. Both flaws were addressed by OpenAI shortly after being reported. The Codex tool is widely used for coding assistance, making these vulnerabilities particularly concerning for developers. The researchers emphasized the lack of opt-in mechanisms for security features in Codex. The vulnerabilities highlight the importance of rigorous security practices in AI development tools.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-12
Vulnerabilities reported to OpenAI
Researchers reported Heapjack and Overpatch vulnerabilities to OpenAI, highlighting critical security flaws in Codex.
BleepingComputer
2026-08-20
Vulnerabilities patched
OpenAI patched both Heapjack and Overpatch vulnerabilities within eight days of their disclosure.
BleepingComputer
2026-09-20
Public disclosure of vulnerabilities
The vulnerabilities were publicly disclosed in articles by BleepingComputer and Accomplish AI, detailing their implications.
BleepingComputer

More articles in this cluster (2)

Following this threat?

Track OpenAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed