Skip to finding
important · RCE — Developer tools

Opening a malicious folder in OpenAI Codex can execute code as the developer user.

Affects

OpenAI Codex, an AI coding agent running on developer workstations.

The folder supplies Git-command arguments containing control sequences that Codex does not sufficiently neutralize before parsing.

Detail and 1 source

The coordinated advisory identifies current-user code execution and says the flaw is patched.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026