CVE-2025-59532 affects Codex CLI, a local coding agent from OpenAI. In versions 0.2.0 through 0.38.0, a flaw in sandbox configuration logic allowed the tool to use a model-generated current working directory as the sandbox writable root. Because that path could reference locations outside the directory where the user originally started the session, the intended workspace boundary was not reliably enforced. As a result, the sandbox policy could be applied to an attacker-influenced or model-influenced path rather than the canonical user session root, enabling writes to arbitrary filesystem locations and execution of commands anywhere the Codex process itself had permission. The issue did not bypass the separate network-disabled sandbox restriction. The vulnerability was fixed in Codex CLI 0.39.0 by canonicalizing and validating the sandbox boundary against the user’s actual session start directory rather than the model-generated path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.