• Sources: primary
  • Summary: Oren Yomtov of Accomplish AI reported two escapes from the Codex sandbox on 2026-08-12 and states OpenAI resolved both within eight days of that report. Heapjack broke out of read-only, the strictest mode, so opening an untrusted repository and asking a question was enough to run commands on the developer machine with no approval prompt. The report credits the fixes to Codex Desktop build 26.818.21641 and Codex CLI 0.149.0 and advises updating to those versions or later, while OpenAI's quoted statement says only that it addressed both issues in August.
  • Why it matters: Both bugs put the enforcement mechanism inside the boundary it was enforcing, so reading an untrusted repository was sufficient for host command execution, continuing the coding-agent sandbox escape thread.
  • Follow-up: Whether OpenAI publishes an advisory or CVE identifier for Heapjack and Overpatch.

send feedback on this story