Codex CLI - Tool

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
December 2, 2025
Last Seen
July 23, 2026

Codex CLI is a tool tracked across 10 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity July 23, 2026.

Overview

Codex CLI is a CLI-based interface around OpenAI's Codex coding agent used to automate coding tasks in development workflows. Recent disclosures describe vulnerabilities in the OpenAI Coding Agent that could let attackers run arbitrary code, creating a risk of remote code execution in developers' environments. This elevates Codex CLI and similar AI-assisted coding tools as a meaningful threat surface in cybersecurity, with implications for.dev workflows, CI/CD, and software supply chains.

Related Threat Clusters

Recent Intelligence Reports

  • [tl;dr sec] #338 - OpenAI and Hugging Face, Accelerating EDR Evasion, Google's Mantis — Tldrsec · July 23, 2026
  • ExploitGym — www.mpi-sp.org · July 22, 2026
  • AI agents can escape sandboxes without ever breaking them — Csoonline · July 21, 2026
  • Attackers Hijack Exposed AI Endpoints to Power Offensive Ops — Darkreading · June 30, 2026
  • OpenAI denies user data exposure from TanStack npm, Mini Shai — Cryptopolitan · May 14, 2026
  • OpenAI Codex Command Injection Flaw Exposes GitHub Tokens — Technadu · March 30, 2026
  • Can AI Agents Boost Ethereum Security? OpenAI and Paradigm Created a Testing Ground — Decrypt.Co · February 18, 2026
  • Linux Foundation aims to become the Switzerland of AI agents — Theregister · December 9, 2025

CVSS v3.1 Breakdown