Codex CLI is a tool tracked across 10 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity July 23, 2026.
Codex CLI is a CLI-based interface around OpenAI's Codex coding agent used to automate coding tasks in development workflows. Recent disclosures describe vulnerabilities in the OpenAI Coding Agent that could let attackers run arbitrary code, creating a risk of remote code execution in developers' environments. This elevates Codex CLI and similar AI-assisted coding tools as a meaningful threat surface in cybersecurity, with implications for.dev workflows, CI/CD, and software supply chains.
A critical command injection vulnerability in OpenAI's Codex has been discovered, allowing attackers to steal GitHub OAuth tokens from developers. The flaw originated from improper input validation during the branch…
Between March and May 2026, Zenity researchers observed three distinct campaigns where attackers hijacked exposed AI endpoints from Ollama and LiteLLM for offensive operations. The attackers exploited inference…
ExploitGym, a benchmark of 898 real-world vulnerabilities, was tested by AI agents including Anthropic’s Claude Mythos Preview and OpenAI’s GPT-5.5. Claude Mythos exploited 157 vulnerabilities, while GPT-5.5 exploited…
Pillar Security has identified vulnerabilities in four AI coding agents—Cursor, Codex, Gemini CLI, and Antigravity—that allow for sandbox escapes without direct attacks on the sandbox itself. These vulnerabilities stem…
OpenAI confirmed a security breach affecting two employee devices due to a supply chain attack linked to the TanStack npm library, part of a broader campaign called Mini Shai-Hulud. The attack involved the publication…
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
OpenAI has patched a vulnerability in its Codex CLI that could be exploited to execute commands, potentially targeting software developers. The vulnerability is tracked as CVE-2025-61260 and poses risks for those using…
A command injection vulnerability in OpenAI's Codex CLI has been identified, allowing attackers to execute arbitrary commands on affected systems. This flaw poses a significant risk to users of the Codex CLI,…
On March 6, 2026, OpenAI announced the launch of Codex Security, a sophisticated application security tool designed to identify software vulnerabilities, available for select ChatGPT users. Concurrently, OpenAnt, an…
The Linux Foundation has established the Agentic AI Foundation (AAIF) to oversee the development of AI agent infrastructure in a vendor-neutral manner. This initiative aims to prevent the fragmentation of AI agents into…