Sev0

AI security incidents, tracked

All incidents / Leaky AI product

Researchers found two sandbox-escape flaws in OpenAI's Codex coding agent

OpenAI, disclosed 15 Sep 2026 Leaky AI product Data exposed Low

What happened

Accomplish AI disclosed two flaws, Overpatch and Heapjack, that let a cloned repository break out of OpenAI Codex's sandbox and run commands on a developer's machine, in one case from the strictest read-only mode with no approval prompt. OpenAI fixed both within about eight days and no exploitation was reported.

Oren Yomtov of Accomplish AI reported two issues. Overpatch, in the open-source Codex CLI, let a crafted patch grant itself write access across the filesystem because the apply_patch tool took write permissions from the untrusted patch content. Heapjack, in Codex Desktop, let untrusted JavaScript in the node_repl tool read a secret token from shared process memory and reach host command execution, working even in read-only mode with no prompt. A developer who opened an untrusted repository could have had commands run outside the sandbox.

How it happened

Leaky AI product: App flaw. A security flaw in an AI application, such as broken login or access checks, let someone reach data they should not have seen.

The AI involved was from OpenAI. The product was Codex, a type of coding assistant.

Impact

Data was exposed. Data involved: source code and credentials. There is no evidence that anyone actually accessed the data.

Severity is rated Low, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm. This was a research finding: no real victims are known.

It became public on 15 Sep 2026.

Accomplish AI reported the flaws to OpenAI on 2026-08-12. OpenAI fixed both in Codex CLI 0.149.0 and Codex Desktop build 26.818.21641, roughly eight days later. No CVEs were assigned.

Sources

  1. https://accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/
  2. https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/

Related incidents

Cite as: Sev0, "Researchers found two sandbox-escape flaws in OpenAI's Codex coding agent", https://sev0.fyi/incidents/2026-09-15-openai-codex-sandbox-escape-heapjack-overpatch/. Data for this record: incidents.json.