Two sandbox escapes let OpenAI Codex run commands on a developer’s host
Researchers found two ways out of OpenAI’s Codex sandbox, one capable of running commands on a developer’s machine from the most locked-down mode, with no prompt and nothing on screen. Update Codex and never run a coding agent with access to the Docker socket or your home directory.