Researchers escape OpenAI Codex sandbox to run commands on host
A sandbox that enforces its own boundaries from inside the thing it is sandboxing isn’t a sandbox. Two Codex escapes make the point: Heapjack pulls auth tokens out of the V8 heap via v8.getHeapSnapshot() from read-only mode, and Overpatch abuses apply_patch symlinks to rewrite your .zshrc in workspace-write mode. Reported 12 August, fixed in eight days (Desktop 26.818.21641, CLI 0.149.0). Check what version your team is pinned to.