OpenAI Codex CLI Command Injection Vulnerability Let Attackers Execute Arbitrary Commands
ID: 1ad19fb6-d124-505a-add1-de38303e54c8
STIX ID: report--1ad19fb6-d124-505a-add1-de38303e54c8
Feed Name: cybersecurityNews.com
OpenAI patched a command‑injection flaw in Codex CLI that let repository-local configuration (.env plus .codex/config.toml) cause automatic execution of attacker-controlled commands when the codex command ran. Check Point Research demonstrated a PoC (e.g., launching macOS Calculator) and warned of risks including reverse shells, key/token exfiltration, code tampering, and supply‑chain propagation; OpenAI fixed the issue in v0.23.0 and users should upgrade and treat repo-level MCP config as review-required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
