build1 publisher
Untrusted JavaScript found Codex's auth token in the shared V8 heap and ran a host command
Researchers escaped the OpenAI Codex sandbox twice, writing outside the workspace in workspace-write mode and launching a host application from read-only mode. Both bugs were fixed within eight days of being reported.
Publishers:dev.to
Reality
- Evidence58
- Adoption22
- Hype gap+18
- Incentives55
- Confidence55