OpenAI Patches Codex Sandbox Flaws After Researchers Escape Twice
Two sandbox escape techniques from OpenAI Codex, including one that ran commands on a developer's machine, have been patched.
Security researchers have demonstrated two methods for escaping OpenAI's Codex sandbox. In one of the attacks, they were able to run commands on a developer's machine even when the sandbox was in its most locked-down mode.
Both vulnerabilities have now been patched by OpenAI. The findings highlight the difficulty of containing AI coding agents, which are designed to execute code and interact with external systems.
This report is based on a single source, so there are no conflicting accounts to compare. The key takeaway is that both escape techniques were fixed before the details became public.
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.