<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct" -->

---
title: Researchers escape OpenAI Codex sandbox to run commands...
description: Security researchers Oren Yomtov of Accomplish AI found two ways to escape OpenAI Codex&#x27;s sandbox. Heapjack exploits a shared memory heap between trusted and...
canonical: https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Researchers escape OpenAI Codex sandbox to run commands on host | daily.dev
og:description: Security researchers Oren Yomtov of Accomplish AI found two ways to escape OpenAI Codex&#x27;s sandbox. Heapjack exploits a shared memory heap between trusted and...
og:url: https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct
og:image: https://api.daily.dev/og/posts/Wdkcv7LCt.png
og:image:alt: Researchers escape OpenAI Codex sandbox to run commands on host
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Researchers escape OpenAI Codex sandbox to run commands on host

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 5 min read · 1 upvotes · 0 comments

## Summary

Security researchers Oren Yomtov of Accomplish AI found two ways to escape OpenAI Codex's sandbox. Heapjack exploits a shared memory heap between trusted and untrusted JavaScript contexts in Codex Desktop's node_repl component, letting an attacker steal an authorization token and achieve unsandboxed command execution just by having Codex analyze a malicious repository, even in the strictest read-only sandbox mode. Overpatch abuses Codex CLI's apply_patch tool, which derives write permissions from attacker-supplied paths, to escape workspace-write restrictions and write to the home directory via a symlink, executing code the next time a terminal opens. Both bugs were reported August 12, 2026 and patched within eight days. OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0; users are urged to update.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host>

## Questions this post answers

### What versions of OpenAI Codex fix the Heapjack and Overpatch sandbox escape vulnerabilities?

OpenAI fixed the Heapjack sandbox escape in Codex Desktop build 26.818.21641 and the Overpatch escape in Codex CLI version 0.149.0. Both vulnerabilities were reported by Oren Yomtov of Accomplish AI on August 12, 2026, and patched within eight days. Developers should update to these versions or later to avoid unsandboxed command execution.

_Developers running Codex should track patch versions like this on daily.dev before trusting agent output on untrusted repos._

### How does the Heapjack exploit break out of the OpenAI Codex sandbox?

Heapjack exploits node_repl, a component Codex Desktop writes into the shared config file, which runs trusted and untrusted JavaScript in the same Node.js process sharing one memory heap. Untrusted code snapshots the heap with v8.getHeapSnapshot() to brute-force a random authorization token, then uses it to send commands through the trusted pipe to an unsandboxed parent process, achieving code execution even in the strictest read-only mode.

_Anyone evaluating AI coding agent security can follow sandbox escape research like this via daily.dev._

### How did the Overpatch vulnerability let Codex CLI write outside the workspace directory?

Overpatch abuses Codex CLI's apply_patch tool, which grants write access to the parent folder of any path named in a patch rather than validating against the workspace boundary. Naming '/tmp' in a patch grants write access to the disk root, so a patch combining a '/tmp' reference with a symlinked write to '.zshrc' lets an attacker append a line that executes unsandboxed the next time a terminal opens.

_Teams hardening AI agent sandboxes can watch for exploit patterns like this through daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#ai-agents](https://daily.dev/tags/ai-agents), [#openai-codex](https://daily.dev/tags/openai-codex)

[View this post on daily.dev](https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Researchers escape OpenAI Codex sandbox to run commands on host","url":"https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct"},"datePublished":"2026-09-20T12:06:01.976Z","dateModified":"2026-09-20T12:06:25.169Z","description":"Security researchers Oren Yomtov of Accomplish AI found two ways to escape OpenAI Codex's sandbox. Heapjack exploits a shared memory heap between trusted and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4944f13a74a532244b6aa6bdf3a8b5b2?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4944f13a74a532244b6aa6bdf3a8b5b2?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ai-agents,openai-codex","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Researchers escape OpenAI Codex sandbox to run commands on host"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/researchers-escape-openai-codex-sandbox-to-run-commands-on-host-wdkcv7lct#faq","mainEntity":[{"@type":"Question","name":"What versions of OpenAI Codex fix the Heapjack and Overpatch sandbox escape vulnerabilities?","acceptedAnswer":{"@type":"Answer","text":"OpenAI fixed the Heapjack sandbox escape in Codex Desktop build 26.818.21641 and the Overpatch escape in Codex CLI version 0.149.0. Both vulnerabilities were reported by Oren Yomtov of Accomplish AI on August 12, 2026, and patched within eight days. Developers should update to these versions or later to avoid unsandboxed command execution. Developers running Codex should track patch versions like this on daily.dev before trusting agent output on untrusted repos."}},{"@type":"Question","name":"How does the Heapjack exploit break out of the OpenAI Codex sandbox?","acceptedAnswer":{"@type":"Answer","text":"Heapjack exploits node_repl, a component Codex Desktop writes into the shared config file, which runs trusted and untrusted JavaScript in the same Node.js process sharing one memory heap. Untrusted code snapshots the heap with v8.getHeapSnapshot() to brute-force a random authorization token, then uses it to send commands through the trusted pipe to an unsandboxed parent process, achieving code execution even in the strictest read-only mode. Anyone evaluating AI coding agent security can follow sandbox escape research like this via daily.dev."}},{"@type":"Question","name":"How did the Overpatch vulnerability let Codex CLI write outside the workspace directory?","acceptedAnswer":{"@type":"Answer","text":"Overpatch abuses Codex CLI's apply_patch tool, which grants write access to the parent folder of any path named in a patch rather than validating against the workspace boundary. Naming '/tmp' in a patch grants write access to the disk root, so a patch combining a '/tmp' reference with a symlinked write to '.zshrc' lets an attacker append a line that executes unsandboxed the next time a terminal opens. Teams hardening AI agent sandboxes can watch for exploit patterns like this through daily.dev."}}]}
```

