Multiple Remote Code Execution Vulnerabilities in OpenAI Codex Disclosed
Article Content
Four vulnerabilities affecting OpenAI Codex have been disclosed, all allowing remote code execution via user interaction. These vulnerabilities arise from improper handling of control sequences and lack of sanitization of configuration settings. Users must either open a malicious folder or visit a malicious page to exploit these vulnerabilities. The vulnerabilities are identified as ZDI-26-649, ZDI-26-648, ZDI-26-651, and ZDI-26-650, with the first two requiring interaction with malicious files or pages, while the latter two involve malicious folders. OpenAI has issued updates to address these vulnerabilities. The advisories were publicly released on September 10, 2026, following their reporting to the vendor on June 2, 2026. The vulnerabilities impact installations of OpenAI Codex, potentially allowing attackers to execute arbitrary code in the context of the current user.
Key Points: • Four remote code execution vulnerabilities in OpenAI Codex disclosed on September 10, 2026. • User interaction is required for exploitation, either by opening malicious folders or files. • OpenAI has released updates to mitigate these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.