TLDRocket
Sign in

OpenAI patched two reported exploits that allowed code to escape the Codex sandbox and run commands outside it

Security issue Provisional 78% confidence first seen

Two separate sandbox-escape vulnerabilities in OpenAI Codex were reported on August 12, 2026, including one in the Codex CLI patch flow and another in the Codex Desktop JavaScript tool. OpenAI fixed both issues within eight days by updating Codex to close the identified sandbox-permission and cross-context execution paths, preventing the previously described unsandboxed command execution.

Source coverage

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.