Researchers break out of OpenAI Codex sandbox, run host commands
Security researchers found two ways to escape OpenAI's Codex sandbox, including one that executes commands on a developer's machine from locked-down mode.
What to know
- Two sandbox escape methods were discovered in OpenAI's Codex, one bypassing the most restrictive execution mode.
- The vulnerabilities allowed researchers to run arbitrary commands on the host system.
- OpenAI has already patched both flaws.
OpenAI has a pattern of poor security practices in both software and ML systems.
-
“Such bad # swsec that it reminds me of the old days. OpenAI has shown over and over again that they are not good at # swsec (which implies that their # MLsec will be of the same poor caliber).”
cigitalgem@sigmoid.social · Mastodon ↗
“Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode.”
Ax Sharma, Bleeping Computer reporter · Bleeping Computer ↗
OpenAI Codex developer
How it unfolded 1 development · click the chart to see its coverage posts
-
1
Researchers disclose Codex sandbox escapes
Security researchers revealed they successfully escaped OpenAI's Codex sandbox through two separate methods, one of which could execute commands on a developer's machine even in the most locked-down mode. OpenAI confirmed patching both vulnerabilities.
-
2 outlets first by Gulf News, 2d ago · also BleepingComputer · read ↗
-
C
Such bad # swsec that it reminds me of the old days. OpenAI has shown over and over again that they are not good at # swsec (which implies that their # MLsec will be of the same poor caliber). https://www. bleepingcomputer.com/news/secu rity/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/
-
What people are saying 1 voices from 1 site · best of 2 · verbatim
- Sep 19
-
0
"Both bugs have the same shape. The thing doing the enforcement was sitting inside the thing being enforced." I continue to be ground to dust by how no-one at the AI labs knows what a "sandbox" actually is, and they all refuse to find out. (This blog post is by a company that is selling its own LLM assessment/benchmarking services.) https://www…