Researchers Describe Two Ways to Bypass the OpenAI Codex Sandbox

Researchers from Accomplish said they found two bugs in Codex that could cross the sandbox boundary. They say OpenAI fixed them; a separate official advisory is still unavailable.

The OpenAI Codex sandbox was allegedly bypassed using two techniques, according to researchers. Security researcher Oren Yomtov of Accomplish published them on September 15, 2026, under the names Overpatch and Heapjack. The findings were reportedly related to local Codex CLI and Codex Desktop clients. According to the researchers, both bugs were reported to OpenAI on August 12 and fixed within eight days.

OpenAI documentation states that the Codex sandbox is intended to restrict file writes, network access, and access to protected paths. Operations outside this boundary are normally supposed to require user approval. However, the researchers claim that these restrictions could be bypassed in two separate cases.

Bypassing the OpenAI Codex Sandbox with Overpatch

The first technique, Overpatch, reportedly affected Codex CLI in workspace-write mode. This mode is intended to allow writing within the working directory, but not outside it. The researchers said they were able to extend write permissions beyond the working directory without displaying an approval prompt.

When working with an untrusted or cloned repository, malicious content could therefore, according to the described scenario, lead Codex to perform operations outside the expected project space. However, the available materials refer to controlled proof-of-concept tests, not confirmed exploitation against users.

Heapjack Was Allegedly Able to Affect Read-Only Mode

The second technique, called Heapjack, was reportedly more serious in terms of the stated restrictions. Accomplish claims that it exploited a tool installed with the Codex Desktop application and enabled an unauthorized command to be executed on the host system even in read-only mode.

read-only mode is intended to be the strictest restriction on the client’s interaction with the system. The case therefore highlights that the boundaries of coding agents may depend not only on the model’s instructions, but also on auxiliary tools and client configuration.

This is not a confirmed breach of OpenAI’s cloud infrastructure. The described impact concerns local use of Codex on a user’s device.

Recommended Codex Updates

Accomplish recommends using at least Codex CLI version 0.149.0 and Codex Desktop build 26.818.21641. Users of older clients should verify the update and avoid opening untrusted repositories in an outdated environment.

  • Codex CLI: version 0.149.0 or later.
  • Codex Desktop: build 26.818.21641 or later.
  • When working with third-party code, use an updated client and exercise caution with cloned repositories.

OpenAI has not yet publicly issued a separate security advisory, CVE, or GHSA explicitly confirming Overpatch, Heapjack, and the listed fixed versions. The scope of affected platforms, configurations, and older releases also remains incompletely documented publicly.

Further developments will depend primarily on any official statement from OpenAI, independent verification of the reproducibility of both techniques, and any evidence of exploitation beyond research tests.

Sources

  • Accomplish Blog – Researchers’ primary claims about the two techniques, the reporting date, the alleged fix, and recommended versions.
  • OpenAI – Description of the intended Codex sandbox boundaries, approval for actions outside the sandbox, and security controls.
  • BleepingComputer – Independent coverage of the findings, including the claim that researchers found two escapes and that fixes were released.

Verified and updated: September 20, 2026 15:20

Sharing