- Sources: primary, Claude Code escape, Cursor CLI escape
- Summary: Accomplish, a vendor selling VM-isolated agent environments, describes two escapes from the OpenAI Codex sandbox and states both were reported to OpenAI on 2026-08-12 and fixed within eight days. Overpatch abuses apply_patch granting write access to the parent directory of every path in a patch, so naming /tmp widens the grant to the filesystem root and a symlinked write reaches .zshrc with no approval prompt. Heapjack recovers the trusted-context token from a V8 heap snapshot inside the node_repl tool that Codex Desktop writes into the global config with no opt-out, then forges requests on the stdout pipe shared by both contexts to reach unsandboxed execution from read-only mode. The post names no affected and no fixed version for Codex CLI or Codex Desktop, so the versions are not known from this source.
- Why it matters: The same vendor published a Claude Code escape on 2026-09-11, fixed in Claude Code 2.1.247, and a Cursor CLI escape on 2026-09-12, so opening an untrusted repository under a sandboxed agent has now failed on three harnesses where the enforcement ran inside the process it was enforcing.
- Follow-up: Track whether any vendor moves agent sandboxing outside the agent process rather than patching individual escapes.
send feedback on this story