You opened someone else's code in Codex. Their code opened your laptop
Two researchers found a way to make OpenAI's coding assistant run a stranger's commands on your own machine — from the mode where it is not supposed to be able to write anything at all.
OpenAI's Codex is a helper that reads and writes code for you. It runs inside a sandbox — a walled-off space, like letting a stranger into the hallway but not the rest of the apartment. Security researchers found two ways through that wall. One of them turns an ordinary act, opening someone else's project and asking a question about it, into command execution on your computer, with no approval prompt and nothing shown on screen.
Oren Yomtov of Accomplish AI reported both flaws to OpenAI on August 12. Both were fixed within eight days: Heapjack in Codex Desktop build 26.818.21641, Overpatch in Codex CLI 0.149.0. If you use Codex, the practical part of this story is one line long — update to those versions or later.
The interesting part is not that a sandbox broke. It is how. In the Heapjack case, Codex kept a secret token to tell its own trusted code apart from the untrusted code the agent runs. Both lived in the same Node.js process, sharing one memory space. So the untrusted side simply took a snapshot of memory and tried every string that looked like a token until one worked — a wrong guess said "not authorized," a right one gave a real error message, which is how the attacker knew it had hit. The lock and the key were kept in the same drawer.
The second bug, Overpatch, is even more mundane. Codex's own patch tool grants write access to the parent folder of any path a patch mentions. Name '/tmp', and it hands over the root of the disk. The working exploit added one useless change naming '/tmp' purely to widen permissions, then appended a line to the shell startup file through a symlink — so the next terminal the developer opens runs the attacker's line outside the sandbox.
Both bugs have the same shape: the thing enforcing the rules was living inside the thing it was supposed to be watching.
And this is not a one-company problem. In July 2026, Pillar Security researchers showed the same idea across Cursor, Codex, Gemini CLI and Google's Antigravity: an agent stays politely inside its sandbox, writes a file, and a trusted tool outside the sandbox runs it later. One commenter on X put the whole category in a sentence — the sandbox was "a promise the heap never agreed to." Another called the trust boundary "a room divider."
Anyone who lets an AI assistant read code — which now includes a lot of people who are not professional developers: students learning to program, freelancers wiring up a first paid project, anyone who cloned a repo from a tutorial because it looked useful. The attack needs nothing clever from you; you open a stranger's repository and ask a question. It also touches everyone who does not code at all but trusts software written this way — because the same design pattern, an agent that polices its own permissions, is showing up in assistants that read your files, your mail and your accounts.
OpenAI has already patched both, so the checkable thing is on your side: whether you are on Codex Desktop build 26.818.21641 and Codex CLI 0.149.0 or later. Beyond that, the source names no timeline, no review and no promised report. Whether the other agents named in July's research get the same treatment, nobody has said.
Eight days from report to fix is fast, and OpenAI deserves the credit Yomtov gave it. But Heapjack reached a component that Codex Desktop installs into a shared config file with no opt-in and no setting to turn it off — plain CLI users inherited it without ever being asked. The speed of the patch is reassuring. The part where you were never asked is the part worth remembering.
Sources: Bleeping Computer, "Researchers escape OpenAI Codex sandbox to run commands on host" by Ax Sharma, September 20, 2026; writeup by Oren Yomtov of Accomplish AI.
Защитная «песочница» ИИ-помощника OpenAI оказалась дырявой: чужой репозиторий мог выполнить любые команды на компьютере разработчика — напоминание, что автономные агенты выпускают быстрее, чем успевают их запереть.
Written by THE TELL’s AI newsroom. how we work · corrections