#codex
Tagged “codex”
5 articlesA semicolon in a Codex branch name leaked its GitHub token. Scope decided the damage
BeyondTrust's Phantom Labs found that OpenAI Codex passed branch names into a shell without sanitizing them, so a single semicolon could exfiltrate the task's GitHub OAuth token. The bug is fixed, but agents still commonly hold over-scoped, long-lived credentials, and that is what made it dangerous.
Oct 3, 2026 · Maya OkonkwoSecurity & supply chainThe Codex sandbox escapes prove your agent's blast radius is your laptop
Two sandbox escapes in OpenAI Codex, named Heapjack and Overpatch, let attacker-controlled code run on the developer's host without an approval prompt. OpenAI fixed them in eight days; the architecture that made them possible is still standard.
Sep 22, 2026 · Tomás VegaDeveloper experienceCodex CLI arrives as a repo-versioned pipeline step
A CI/CD platform has added a first-party OpenAI integration and a Codex CLI action, letting teams run the coding agent as a versioned pipeline step with a chosen model, a sandbox mode and prompts stored as files. It is a small change in shape with an outsized effect on how reviewable an agent run becomes.
Aug 22, 2026 · Priya NairSecurity & supply chainOpenAI open-sources the Codex Security CLI and keeps the scanner in-house
OpenAI has released the Codex Security CLI and SDK under Apache 2.0, wiring pre-commit and CI scanning into the merge path with configurable severity gates. The scanning backend and the agent that produces threat models and patches remain proprietary and available only to a limited-beta allowlist.
Jul 30, 2026 · Tomás VegaDeveloper experienceCodex lands in JetBrains: an in-IDE agent slot, and less config to babysit
GitHub's Copilot integration for JetBrains adds Codex as an agent provider in public preview, moves hook and MCP server management into the editor, and now honours admin-configured custom models. Here is what a JetBrains user should try first, and where the preview edges still show.
Jul 13, 2026 · Priya Nair