The OpenAI Codex desktop app for macOS is vulnerable to a remote image URL exfiltration attack. An attacker can induce the model to construct a remote image URL containing sensitive data, which the app automatically fetches and sends to an attacker-controlled server. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The app's rendering of remote images from Markdown in model responses a [truncated]
A cross-site scripting vulnerability was discovered in OpenAI Atlas before version 1.2025.288.15. The issue exposed privileged browser APIs to web content on *.openai.com origins, which could be exploited via a cross-site scripting vulnerability in forum.openai.com. This could allow attackers to access browser history information and open or close tabs. The vulnerability has been addressed in OpenAI Atlas [truncated]
A critical vulnerability was identified in OpenAI Codex CLI v0.23.0 and earlier. The vulnerability enables code execution through malicious MCP (Model Context Protocol) configuration files when a user runs the codex command inside a malicious or compromised repository. This vulnerability has a CVSS score of 9.8, indicating a critical severity level. Users of OpenAI Codex CLI, especially those using versio [truncated]