// Alert

Openai threat report

Security researchers from Novee disclosed critical flaws in OpenAI Codex's multi-pass agent workflow that enable remote code execution and supply-chain attacks. An attacker can craft a malicious GitHub issue to inject instructions into a shared workspace; a subsequent more-privileged Codex invocation loads and executes the attacker-authored instructions despite output validation, potentially leading to repository takeover and secrets exposure. OpenAI has strengthened its workflows by separating agent passes and restricting workspace access.

// Get alerts for Openai