Researchers escape OpenAI Codex sandbox to run commands on host

Cybersecurity · September 21, 2026

Cybersecurity·bleepingcomputer.com

Security researchers found two separate ways to break out of OpenAI's Codex sandbox, including one exploit that let them execute commands directly on a developer's host machine even from the tool's most locked-down mode. OpenAI has since shipped fixes for both escape routes. The findings are a reminder that AI coding agents built to run untrusted code still need airtight isolation.

// source: bleepingcomputer.com ↗

Back to Blog