Security Researchers Escape OpenAI Codex Sandbox, Execute Host Commands
Two vulnerabilities allowed command execution even in locked-down mode; OpenAI has issued patches

Key Takeaways
- Two sandbox escape vulnerabilities were discovered in OpenAI Codex, allowing command execution on host machines.
- One escape worked even in the most restrictive sandbox mode, raising concerns about AI tool isolation.
- OpenAI has patched both issues; users should update to the latest version immediately.
- The findings serve as a reminder to audit and harden AI-assisted development environments.
Quick answers
- What happened?
- Security researchers demonstrated two methods to escape the OpenAI Codex sandbox, with one bypassing the most restrictive lockdown to execute arbitrary commands on a developer's host machine. OpenAI has confirmed both issues and released patches. The findings highlight the ongoing challenges in securing AI-assisted coding tools and the importance of applying updates promptly.
- Which products are affected?
- Codex
- What should defenders do?
- Users should update OpenAI Codex to the latest available version. Admins should monitor OpenAI security advisories for further guidance and apply recommended configuration changes.
According to reporting from BleepingComputer, security researchers identified two sandbox escape vulnerabilities in OpenAI's Codex platform. The escapes allowed command execution on a developer's host machine, including from the service's most locked-down operational mode. OpenAI has stated that both vulnerabilities have been patched. The company advises users to ensure they are running the latest version of Codex to mitigate the risks. The exact technical details of the escapes and the potential for real-world exploitation remain under investigation, but the incidents underscore the need for rigorous sandboxing and rapid patching in AI development environments.
Security Details
Two sandbox escape vulnerabilities in OpenAI Codex allowed arbitrary command execution on developer host machines, including from locked-down modes. Patches have been released by OpenAI.
Affected products
Codex
Mitigation
Users should update OpenAI Codex to the latest available version. Admins should monitor OpenAI security advisories for further guidance and apply recommended configuration changes.
Sources
BleepingComputer
Researchers escape OpenAI Codex sandbox to run commands on host
Sep 20, 2026 · 12:00
Original link
Related Security News

AI Agents Introduce New Lateral Movement Vectors in Cybersecurity Landscape
A recent analysis published on The Hacker News examines how AI agents differ from deterministic applications in cybersecurity operations, raising concerns about autonomous path discovery and task completion capabilities. The report highlights that AI agents can relentlessly pursue task completion, potentially discovering and exploiting unexpected access paths that traditional least-privilege models may not address.




