Researchers Found Two Sandbox Escape Flaws in OpenAI Codex, Both Now Patched
Security researchers disclosed two techniques, dubbed Overpatch and Heapjack, that could bypass OpenAI Codex's sandbox restrictions and execute commands on the host machine. Overpatch exploited a flaw in how the apply_patch function derived write permissions, allowing files outside the workspace to be modified even in workspace-write mode. Heapjack targeted the shared V8 heap in Codex Desktop's Node.js environment, enabling untrusted code to recover an authorization token and forge requests accepted by the unsandboxed parent process. Both vulnerabilities could be triggered by a developer simply opening a malicious repository and asking a question. OpenAI patched both issues within eight days of the responsible disclosure, and no real-world exploitation has been reported.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in