@openai/codex is vulnerable to Protection Mechanism Failure
42
Medium Risk
In affected builds, the unified-exec zsh-fork path could mishandle user-approved sandbox decisions around permission profiles, and codex sandbox did not always enforce proxy-only networking when a configured sandbox network proxy was active. Together these could weaken intended containment: for example, denied-read restrictions might not be preserved consistently after parent command approval, or sandboxed commands could reach the network outside the configured proxy path. The fix preserves approval semantics for unified exec and enforces proxy-only containment whenever an active sandbox proxy is running.
You are affected if you are using a version that falls within the vulnerable range.
@openai/codex is vulnerable to Protection Mechanism Failure in versions 0.137.0 - 0.138.0.
Upgrade the @openai/codex library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant