Third sandbox escape: OpenAI's Codex breached via CLI and Rust heap attack

EdenEmarco177 · x · 2026-09-15

Security researcher @orcaman published a third AI coding tool sandbox escape writeup — after Claude Code and Cursor, this time it's OpenAI's Codex.

Two notable escapes:

Found by @Accomplishai researcher orenyomtov, both issues were quickly fixed by OpenAI. Full details in the writeup.

Original post →

More from coding & agent

coding & agent channel →