Junglewise Threat Intelligence

CVE-2025-59532: OpenAI Codex sandbox bypass in path configuration

CVE-2025-59532 · Severity: medium · CVSS 4 · Published 2025-09-19

Vendors: npm, OpenAI.

Executive brief

Codex is a command-line development tool that uses a sandbox to isolate execution of code and file operations. A flaw in the sandbox's path configuration logic allows an attacker with low privileges to write arbitrary files and execute commands outside the intended workspace boundary, potentially compromising the host system where Codex runs.

Technical details

The vulnerability is a path validation error (CWE-20) in Codex CLI's sandbox configuration logic. The sandbox was designed to restrict file operations and command execution to a specific workspace folder; however, a bug allowed the sandbox to treat model-generated working directories as the sandbox root, including paths outside the user's starting session directory. This bypasses the intended workspace boundary. The attack requires low privileges (user interaction, passive) and network access. An attacker can achieve arbitrary file writes and command execution with the permissions of the Codex process. The issue does not affect the network-disabled sandbox restriction. Codex CLI 0.39.0 and IDE Extension 0.4.12 contain fixes that canonicalize and validate sandbox boundaries based on the user's session start directory.

Affected products

  • OpenAI Codex 0.2.0 to 0.38.0
  • OpenAI Codex IDE Extension 0.4.11 and earlier

Timeline

  • 2025-09-19: disclosed: Public advisory GHSA-w5fx-fh39-j5rw published
  • 2025-09-19: patched: Codex CLI 0.39.0 released with sandbox boundary fix
  • 2025-09-19: patched: Codex IDE Extension 0.4.12 released with sandbox boundary fix

References

Related threats