Summary
- Researchers reported two Codex sandbox weaknesses to OpenAI on 12 August, and both were fixed within eight days.
- Heapjack could escape read-only mode into unsandboxed host command execution, while Overpatch could bypass workspace-write restrictions.
- The flaws show how privileged helper mechanisms can weaken agent isolation even where the model itself remains inside a nominal sandbox.
Researchers found two weaknesses in OpenAI Codex that could cross intended sandbox boundaries and reach parts of a developer’s host system, including one route from the product’s read-only mode to unsandboxed command execution.
Both issues were privately reported to OpenAI on 12 August 2026 and fixed within eight days, according to Oren Yomtov, Principal Security Researcher at Accomplish. They were therefore remediated before the research was made public in September.
The first issue, named Heapjack, affected a JavaScript tool used by Codex Desktop. The sandbox itself remained in place, but a secret used to distinguish trusted from untrusted operations was held in memory accessible from the untrusted JavaScript context.
That allowed the researcher to obtain the token and cause a parent process outside the sandbox to execute commands on the host. The route worked from read-only mode, which is intended to prevent the agent from writing to the local system.
The second issue, called Overpatch, affected the open-source Codex command-line tool in workspace-write mode. Codex’s apply_patch mechanism determined write permissions partly from paths supplied inside the patch itself.
By including an additional path that widened the permission grant, the researcher was able to get the patch mechanism to modify a file outside the intended project workspace. The technique could write through a symbolic link into the user’s home directory without the approval prompt expected for such an action.
The two vulnerabilities used different mechanisms but shared a broader architectural weakness: part of the enforcement logic trusted information available from inside, or closely adjacent to, the environment it was supposed to constrain.
Accomplish said OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0. Users on those versions or later are not affected by the disclosed issues.
There is no public evidence that either vulnerability was exploited against Codex users before remediation. The disclosure is therefore an architectural security story rather than an active incident.
That architecture is becoming more consequential as coding agents receive broader access to local development environments. A repository can contain untrusted content while the agent analysing it may also have access to shell commands, patching tools, source files, dependency managers, and other local capabilities.
The sandbox is meant to separate those two trust levels. If privileged helper processes or shared state create an indirect path around the restriction, the permission label presented to the user may describe only part of the actual security boundary.
The issue has parallels with the DeepSeek coding-agent weakness previously covered by Cyber Insider, where a different implementation allowed a sandboxed agent to interfere with its own execution controls.
The underlying problem extends beyond any single model. Coding-agent security depends on the interaction between model behaviour, local permissions, operating-system isolation, helper tools, repository content, and the controls that mediate transitions between those layers.
Because Heapjack and Overpatch were fixed before publication, there is no current unpatched exposure in the versions identified by the researchers. The disclosure instead shows why agent containment has become a core software-security property as development tools gain the ability to move from reading code towards acting directly on the host that contains it.





