Intel

AIKIDO-2026-604998

@openai/codex is vulnerable to Protection Mechanism Failure

Protection Mechanism Failure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Today

42

Medium Risk

This Affects:

JS@openai/codex
0.137.0 - 0.138.0
Fixed in 0.139.0
Are you affected? Scan for Free

TL;DR

In affected builds, the unified-exec zsh-fork path could mishandle user-approved sandbox decisions around permission profiles, and codex sandbox did not always enforce proxy-only networking when a configured sandbox network proxy was active. Together these could weaken intended containment: for example, denied-read restrictions might not be preserved consistently after parent command approval, or sandboxed commands could reach the network outside the configured proxy path. The fix preserves approval semantics for unified exec and enforces proxy-only containment whenever an active sandbox proxy is running.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@openai/codex is vulnerable to Protection Mechanism Failure in versions 0.137.0 - 0.138.0.

How to fix this

Upgrade the @openai/codex library to the patch version.