2026-10-11 17:13 UTC

Accomplish AI’s Oren Yomtov claims the now-patched Heapjack and Overpatch flaws let untrusted Codex execution cross into host privileges through shared-heap credentials and patch-derived permissions, requiring affected Desktop and CLI installations to update rather than trust sandbox mode alone.

state: watchingheat: mediumuncertainty: mediumconvergesscott: mediumagentic-security sandbox-escape coding-agentsOren YomtovAccomplish AIOpenAI

What is this?

The case concerns alleged Codex sandbox escapes called Heapjack and Overpatch, attributed to Accomplish AI researcher Oren Yomtov. The supplied Accomplish blog identifies Yomtov as Principal Security Researcher but discusses a different escape affecting Claude Cowork, so it does not establish the Codex exploit mechanisms, affected installations, or claimed fix timeline. The only Codex-specific snippet says Overpatch writes into a VM and Heapjack opens an app inside it, with the VM remaining a containment boundary; this leaves the case’s claim of host access unverified and potentially dependent on deployment architecture.

Why it matters to Scott

The reported containment failure converges with Scott’s SiloOS requirement for credential-separated execution and independently controlled exits, and warrants checking the actual boundaries around his Codex-driven Superlever worktrees and Bubblewrap-isolated Songbird workers. This is not the same development as any supplied radar episode, but the grounding leaves host escape, affected versions and remediation unverified, so it supports an exposure check rather than a confirmed patch directive or a strong public convergence claim.
ip:framework.siloosip:concept.sandboxed-executiondev:project.superleverdev:technology.bubblewrapdev:technology.codex-cliradar:coop-coding-agent-vm-isolationradar:brig-microvm-agent-containmentradar:concept.coding-agent-securityradar:concept.credential-isolation
queries asked of Scott's wikis
  • coding agent sandbox trust boundaries host versus VM isolation
  • Codex CLI Desktop usage update management
  • agent harness shared credentials privilege separation
  • patch tool permissions untrusted agent execution
  • prompt injection containment external enforcement

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 505h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-20 15:30 (minted)⭐ origin echo-reconstructedThe researchers describe Heapjack and Overpatch sandbox escapes and report that OpenAI fixed them within eight days of August 12 disclosure,
Oren Yomtov, Accomplish AI on blog (echo) · attributed from hn.story.49776305 · published time unknown
—
09-20 14:35first on hacker news · published · lag ?Researchers escape OpenAI Codex sandbox to run commands on host
Brajeshwar
—
09-20 14:35amplified on hacker newshn.story.49776305
Brajeshwar
peak 1 · 0 comments · 35% of case engagement
09-22 01:29amplified on hacker news 👑hn.story.49795755
CoderLim110
peak 2 · 0 comments · 65% of case engagement
09-20 15:20our radar first saw it · lag ?discovery anchor: hn.story.49776305—
pace: p32 vs 1032 stories at the 336h mark (now 505h old) — ahead of addom-local-coding-harness (1.5x), behind agentsec-static-config-auditing (0.8x)

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnResearchers escape OpenAI Codex sandbox to run commands on host
Retrieved article excerpt

Open article · Retrieved 2026-09-20T15:22:27.062692+00:00

# Researchers escape OpenAI Codex sandbox to run commands on host

By

###### [Ax Sharma](https://www.bleepingcomputer.com/author/ax-sharma/)

- September 20, 2026
- 08:00 AM
- [0](https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/#comment_form)

OpenAI

Security researchers found two ways out of the OpenAI Codex sandbox, one of them capable of running commands on a developer's machine from Codex's most locked-down mode, with no approval prompt and nothing shown on screen.

Both flaws were reported to OpenAI on August 12 and fixed within eight days, according to Oren Yomtov of Accomplish AI.

The more serious of the two, which the researchers call Heapjack, turns a routine action into remote code execution: open someone else's repository in Codex, ask it a question about the code, and whoever wrote that repository gets unsandboxed command execution on your computer.

Codex is OpenAI's coding agent, available as a command-line tool and a desktop app. Like rival agents, it runs the model's actions inside a sandbox so that untrusted code cannot touch the wider system. Both escapes work by defeating that boundary from the inside.

## Heapjack

The Heapjack technique, as described in [Yomtov's writeup](https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/), targets a component called *node\_repl*, which Codex Desktop writes into the global '*~/.codex/config.toml'* file at install time.

There is no opt-in and no setting to turn it off, and because the entry lives in the shared config, plain Codex CLI users inherit the same tool without ever being asked.

*node\_repl* runs a single Node.js process that holds two separate JavaScript execution contexts. One is trusted and contains OpenAI's own code. The other is untrusted and runs the agent's code. The trusted context proves it is trusted by presenting a random token generated fresh on each run.

The problem is that both contexts live in one Node process and share one memory heap, so the token is just a string sitting in memory the untrusted side can read.

The Heapjack attack path (​​​​​Accomplish.ai)

**The Heapjack attack path**(​​​​​Accomplish.ai)

The untrusted code takes a snapshot of the heap with '*v8.getHeapSnapshot()'* and tries every string shaped like a UUID. A wrong guess returns "not authorized." A correct token with a bad argument returns a real validation error, which tells the attacker the token is right.

With the token, the untrusted code writes its own request onto the same pipe the trusted context uses to talk to a native, unsandboxed parent process.

The parent checks the token, sees a valid one, and does the work. The proof of concept used the system's 'open' command to launch an application outside Codex's process tree entirely. The same access reaches any Unix socket, a Docker daemon socket being the obvious target, and a tool for editing the global config file.

All of this runs at read-only, the strictest sandbox mode, where the agent is not supposed to write anything at all.

## Overpatch

The second flaw, Overpatch, sits in the open-source Codex CLI. In workspace-write mode, the agent may only write inside the project folder, and a shell command aimed at the home directory is refused.

The researchers got Codex's own patch tool, apply\_patch, to write there anyway.

The tool grants write access to the parent folder of each path named in a patch. Name '/tmp', and it grants write access to the root of the disk.

The working exploit uses a patch with two changes: one that names '/tmp' and does nothing useful except widen the permission, and one that appends a line to '.zshrc' through a symlink into the home directory.

Remove the first change and the write is refused. With it, the next terminal the developer opens runs the attacker's line unsandboxed.

## The same underlying mistake

Both bugs share a shape: the enforcement mechanism was living inside the thing it was supposed to be enforcing. *apply\_patch* worked out its own permissions from attacker-supplied input. *node\_repl* kept the secret separating trusted from untrusted code in the same memory as the untrusted code.

In each case the sandbox was told, from the inside, to let something through.

The class of bug is not new. In July 2026, [Pillar Security researchers demonstrated](https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/) the same idea across Cursor, Codex, Gemini CLI and Google's Antigravity, where an agent that stays inside its sandbox writes a file a trusted tool outside the sandbox later runs.

Reacting to Yomtov's post on X, one commenter [wrote that](https://x.com/0zSchnack/status/2100164179399242043) "V8 contexts isolate globals, not memory, so the sandbox was really a promise the heap never agreed to." Another called the trust boundary "[a room divider](https://x.com/ctfstudent/status/2100281489774526867)." The default-enabled behavior drew its own scrutiny, with one asking why a privileged token was reachable from untrusted JavaScript at all.

## What to do

OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0, according to Accomplish.

Users should update to those versions or later. Yomtov credited OpenAI with resolving both issues within eight days of his report.

BleepingComputer reached out to OpenAI for comment prior to publishing.

[article image](https://hubs.li/Q04x67m50)

## [Build your security blueprint for AI-powered attacks](https://hubs.li/Q04x67m50)

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

[Save your seat](https://hubs.li/Q04x67m50)

### Related Articles:

[OpenAI admits it didn't disclose rogue AI wiki hijacking incident](https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/)

[Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes](https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/)

[OpenAI details more cases of AI agents taking unauthorized actions](https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/)

[Anthropic wants Claude to analyze your bank account and financial data](https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/)

[OpenAI says ChatGPT outage causes image generation errors](https://www.bleepingcomputer.com/news/technology/openai-says-chatgpt-outage-causes-image-generation-errors/)
Brajeshwar10
🟧 echo.blog ⭐The researchers describe Heapjack and Overpatch sandbox escapes and report that OpenAI fixed them within eight days of August 12 disclosure,Oren Yomtov, Accomplish AI——
🟧 hnEscaping the OpenAI Codex sandbox, twiceCoderLim11020

Interpretation history

Decision trace