// OpenaiMEDIUM
CVE-2026-14898 affects the OpenAI Codex desktop application for macOS. The vulnerability arises from automatic rendering of remote images in Markdown without user interaction, allowing indirect prompt injection attacks to exfiltrate sensitive data such as API keys or proprietary source code. No patched versions or evidence of active exploitation have been identified at disclosure, but the risk is elevated in development environments with access to sensitive systems.
// Get alerts for Openai