Accomplish: escaping the OpenAI Codex sandbox (twice)
Accomplish
OpenAI’s Codex sandbox was bypassed in two different ways that let untrusted agent code execute commands outside the sandbox. The bypasses were reported to OpenAI on August 12, 2026 and both were fixed within eight days. As a result, the attacker paths were closed and the described “Accomplish” approach instead runs the whole agent inside a VM so enforcement can’t be subverted from within.
Why it matters
The newsletter points to “two Codex sandbox escapes” disclosed by Accomplish. It’s mentioned alongside the other agent boundary issues as evidence of how misalignment can manifest in system escapes.