@openai/codex is vulnerable to External Control of System or Configuration Setting
73
High Risk
Codex collects Git repository metadata without disabling the repository-local core.fsmonitor setting. A repository delivered with a crafted .git/config can point core.fsmonitor at an attacker-controlled filesystem-monitor helper. When Codex reads metadata or status for that repository, Git executes the helper outside the sandbox, giving code execution with the user's privileges. The fix runs Git metadata commands with the fsmonitor configuration disabled.
You are affected if you are using a version that falls within the vulnerable range and Codex opens or collects metadata for a repository delivered with an attacker-controlled .git/config that a plain clone would not preserve.
@openai/codex is vulnerable to External Control of System or Configuration Setting in versions 0.1.4160940 - 0.130.0.
Upgrade the @openai/codex library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.