Third sandbox escape: OpenAI's Codex breached via CLI and Rust heap attack
EdenEmarco177 · x · 2026-09-15
Security researcher @orcaman published a third AI coding tool sandbox escape writeup — after Claude Code and Cursor, this time it's OpenAI's Codex.
Two notable escapes:
- One is in the open-source codex CLI, which the author found generally more secure than its competitors.
- The other is in the closed-source Rust-based component, leveraging a sophisticated heap attack.
Found by @Accomplishai researcher orenyomtov, both issues were quickly fixed by OpenAI. Full details in the writeup.
More from coding & agent
- tldraw's AI design sprint: Codex prototypes every discussed interaction overnight, artifacts by day 2 — max__drake · 2026-09-15
- Research agents log what they cite — should they also defend what they reject? — Entire_Mark8010 · 2026-09-15
- Grok Bot Auto-Schedules Pinterest Posts, Writes Titles From Images—Where Claude Failed — prasenx · 2026-09-15
- Amplitude tripled PR volume in six months by fixing CI, not agents — mobileraj · 2026-09-15
- Looking for a minimal, near-instant CLI coding agent for one-off bash tasks — funbike · 2026-09-15
- LangChain's Chase on why agent memory never sticks: deciding what to remember is app-specific — blaizedsouza · 2026-09-15