CVE-2025-54558: Medium severity OpenAI Codex CLI vulnerability
Published Jul 25, 2025
·Updated
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.
Affected Software
2 affected components
OpenAI Codex CLI<0.9.0
Andrew Gallant ripgrep
Event History
Jul 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54558?
CVE-2025-54558 is considered a medium severity vulnerability due to auto-approving execution of potentially harmful commands.
2
How do I fix CVE-2025-54558?
To fix CVE-2025-54558, upgrade OpenAI Codex CLI to version 0.9.0 or later.
3
Which software is affected by CVE-2025-54558?
CVE-2025-54558 affects OpenAI Codex CLI versions before 0.9.0 and can also involve ripgrep under certain conditions.
4
What are the flags that trigger the issue in CVE-2025-54558?
The flags that trigger the issue in CVE-2025-54558 include --pre, --hostname-bin, --search-zip, and -z.
5
What are the potential risks of CVE-2025-54558?
The risks of CVE-2025-54558 include executing unintended commands which may lead to unauthorized access or data breaches.