important · RCE — Developer tools
Opening a malicious folder in OpenAI Codex can execute code as the developer user.
Affects
OpenAI Codex, an AI coding agent running on developer workstations.
The folder supplies Git-command arguments containing control sequences that Codex does not sufficiently neutralize before parsing.
Detail and 1 source
The coordinated advisory identifies current-user code execution and says the flaw is patched.