ZDI-26-305: (0Day) OpenAI Codex Sandbox Escape Vulnerability
This vulnerability allows remote attackers to bypass the sandbox on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must use Codex to process a repository containing malicious JavaScript. The ZDI has assigned a CVSS rating of 8.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-305?
The severity of ZDI-26-305 is critical due to the ease of exploitation and potential impact on security.
How do I fix ZDI-26-305?
To fix ZDI-26-305, ensure that you update to the latest version of OpenAI Codex that addresses this vulnerability.
What are the potential impacts of ZDI-26-305?
The potential impacts of ZDI-26-305 include unauthorized access to sensitive information and system compromise.
Is user interaction required for exploiting ZDI-26-305?
Yes, user interaction is required to exploit ZDI-26-305 as it necessitates processing a repository containing malicious JavaScript.
Which software is affected by ZDI-26-305?
ZDI-26-305 affects installations of OpenAI Codex.