PatchSiren

OpenAI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenAI CVE published 2026-07-06

CVE-2026-14898

The OpenAI Codex desktop app for macOS is vulnerable to a remote image URL exfiltration attack. An attacker can induce the model to construct a remote image URL containing sensitive data, which the app automatically fetches and sends to an attacker-controlled server. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The app's rendering of remote images from Markdown in model responses a [truncated]

MEDIUM OpenAI CVE published 2026-06-05

CVE-2026-11326

A cross-site scripting vulnerability was discovered in OpenAI Atlas before version 1.2025.288.15. The issue exposed privileged browser APIs to web content on *.openai.com origins, which could be exploited via a cross-site scripting vulnerability in forum.openai.com. This could allow attackers to access browser history information and open or close tabs. The vulnerability has been addressed in OpenAI Atlas [truncated]

CRITICAL OpenAI CVE published 2026-04-14

CVE-2025-61260

A critical vulnerability was identified in OpenAI Codex CLI v0.23.0 and earlier. The vulnerability enables code execution through malicious MCP (Model Context Protocol) configuration files when a user runs the codex command inside a malicious or compromised repository. This vulnerability has a CVSS score of 9.8, indicating a critical severity level. Users of OpenAI Codex CLI, especially those using versio [truncated]