216.73.216.6

CVE-2025-55345

· Published 13/08/2025 09:15 · Modified 13/08/2025 20:15

Labels: CVE-2025-55345 2025-08-13CVE-2025-55345CWE-61[email protected]

Essential information

Published
13/08/2025 09:15
Modified
13/08/2025 20:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jfrog / codex cli cpe:2.3:a:jfrog:codex_cli:*:*:*:*:*:*:*:*

References