216.73.217.22

CVE-2025-59532

· Published 22/09/2025 21:16 · Modified 22/09/2025 21:22

Labels: CVE-2025-59532 2025-09-22CVE-2025-59532CWE-20[email protected]

Essential information

Published
22/09/2025 21:16
Modified
22/09/2025 21:22
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandbox’s writable root, including paths outside of the folder where the user started their session. This logic bypassed the intended workspace boundary and enables arbitrary file writes and command execution where the Codex process has permissions - this did not impact the network-disabled sandbox restriction. This issue has been patched in Codex CLI 0.39.0 that canonicalizes and validates that the boundary used for sandbox policy is based on where the user started the session, and not the one generated by the model. Users running 0.38.0 or earlier should update immediately via their package manager or by reinstalling the latest Codex CLI to ensure sandbox boundaries are enforced. If using the Codex IDE extension, users should immediately update to 0.4.12 for a fix of the sandbox issue.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openai / codex cli cpe:2.3:a:openai:codex_cli:0.2.0-0.38.0:*:*:*:*:*:*:*
openai / codex cli cpe:2.3:a:openai:codex_cli:0.39.0:*:*:*:*:*:*:*

References