AE-GR7ZDC99
Coding agent treats a model-generated cwd as the sandbox's writable root, allowing writes and commands outside the workspace
SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH
Because of a bug in Codex CLI's sandbox configuration logic, a working directory generated by the model could be used as the sandbox's writable root, including paths outside the folder where the user started the session. This bypassed the workspace boundary and enabled arbitrary file writes and command execution wherever the Codex process had permissions; the network-disabled restriction was not affected.
- Framework / agent
- OpenAI Codex CLI · terminal coding agent
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY Codex has sandbox bypass due to bug in path configuration logic — https://github.com/openai/codex, retrieved 2026-09-29
- GITHUB COMMIT fix: ensure cwd for conversation and sandbox are separate concerns (#3874) — github.com/openai/codex, retrieved 2026-09-29
Symptoms
- A model-generated cwd outside the session folder becomes the sandbox's writable root
- Arbitrary file writes and command execution occur outside the intended workspace boundary
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-GR7ZDC99. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.