@ai-sdk/harness-codex is vulnerable to Authorization Bypass
63
Medium Risk
The Codex harness in @ai-sdk/harness-codex relays tool calls from sandboxed code to host-exposed tools, and a fallback authorization path accepts any request whose calling process command line contains the allowed Codex CLI shim path. On Linux the relay reads /proc and grants authorization on that path match instead of requiring a model-authorized tool-call event. Untrusted code running in the sandbox, such as a malicious dependency or build script, can therefore invoke arbitrary host tools including secret lookups, deployment operations, and cloud API calls. The fix removes the process-path fallback and only accepts relay requests that match a short-lived, one-time authorization derived from a bridge-observed model event.
You are affected if you are using a version that falls within the vulnerable range and you run the harness on Linux with one or more host-provided tools while untrusted code executes in the sandbox.
@ai-sdk/harness-codex is vulnerable to Authorization Bypass in versions 1.0.12 - 1.0.28.
Upgrade the @ai-sdk/harness-codex library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant