OpenAI remediated two Codex sandbox-escape vulnerabilities, Overpatch and Heapjack, that could allow a malicious repository to execute commands or alter files on a developer's host system. Overpatch affected the open-source Codex CLI's apply_patch authorization logic: attacker-controlled patch paths could expand permitted write locations and, with symlinks, modify files outside the workspace, including shell startup files such as ~/.zshrc.
Heapjack affected Codex Desktop's node_repl integration. Untrusted JavaScript sharing a V8 heap could recover a trusted authorization token, forge requests to an unsandboxed parent process, and perform host-level actions—including when Codex was configured for read-only sandbox use. OpenAI fixed Overpatch in Codex CLI version 0.149.0 and Heapjack in Codex Desktop build 26.818.21641; organizations should update both components and treat untrusted repositories as potentially hostile.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers reported two Codex vulnerabilities, Overpatch and Heapjack, to OpenAI. The flaws could allow attacker-controlled repositories to escape intended sandbox restrictions and execute host-level actions.
OpenAI remediated Overpatch in Codex CLI version 0.149.0 and Heapjack in Codex Desktop build 26.818.21641. Both sources state the issues were addressed in under a week after reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.