CVE-2025-61260 — OpenAI Codex CLI: Command Injection via Project-Local Configuration
ID: 6d8ad942-d023-5afe-a15c-50ee5d20cefe
STIX ID: report--6d8ad942-d023-5afe-a15c-50ee5d20cefe
Feed Name: Check Point Research
Check Point Research discovered and demonstrated a critical vulnerability in the OpenAI Codex CLI that allowed project-local .env and MCP server configuration files to cause automatic execution of attacker-controlled commands when developers ran codex; this could be abused as a stealthy supply-chain backdoor enabling remote code execution, credential theft, CI contamination, and persistent access. The issue was responsibly disclosed and patched in Codex CLI v0.23.0, which prevents project-local redirection of CODEX_HOME.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
