FR
live
tag

#codex

Two sandbox escapes let OpenAI Codex run commands on a developer’s host

Researchers found two ways out of OpenAI’s Codex sandbox, one capable of running commands on a developer’s machine from the most locked-down mode, with no prompt and nothing on screen. Update Codex and never run a coding agent with access to the Docker socket or your home directory.

OpenAI launches the Agents API and turns the Codex harness into a service

OpenAI opened an Agents API in public beta on September 10, 2026, selling Codex’s backend as a service to run agents unattended for days. The same day, the company paused sign-ups for its Pro plan under GPT-6 Astra demand: the bottleneck is shifting from models to infrastructure.

A poisoned .git/config runs code when Claude Code, Codex or Cursor opens a repository

Manifold Security disclosed on 2 September 2026 eight flaws across seven CLI coding agents: a repository delivered as an archive can trigger a local command on open, outside the sandbox and without approval, via Git’s core.fsmonitor setting. Disable core.fsmonitor by default and inspect .git/config before opening a received folder with an agent.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss