OpenAI's Codex Stopped Its Own `/cd` Command From Weakening the Sandbox
Release rust-v0.151.0 files five permission and sandbox items under Bug Fixes, including stale classifications that kept authorising actions after permissions changed.
6d ago

Artificial intelligence, professionally covered
Release rust-v0.151.0 files five permission and sandbox items under Bug Fixes, including stale classifications that kept authorising actions after permissions changed.
6d ago

Release v2.1.251 lists a symlink race that lets file tools act outside approved paths, plugin path traversal and settings that disable audit logging. No advisory.
6d ago

Across six models and 153 tasks the self-poisoning rate is 20.3% to 41.8%. The number that will travel is the one measured when the payload is fitted to the task family.
Aug 27, 2026

The maintainer's account was compromised in June. The advisory reached the GitHub database on 26 August, points at version 0.6.4, and PyPI publishing is suspended.
Aug 27, 2026

CVE-2026-18252 is untrusted-input inclusion: the agent read configuration from a place the user controls. Full details stay embargoed for around 30 days.
Aug 27, 2026

Both advisories went out on 19 August against versions below 0.10.0 — which reached PyPI on 11 June. Fourteen releases have shipped since.
Aug 20, 2026

A time-boxed HackerOne programme with a $50,000 per-report cap, in which escaping to the guest OS explicitly does not count.
Aug 19, 2026

Andreessen Horowitz and Bessemer co-led the Series A for a platform that inventories, monitors and controls the AI agents multiplying inside corporate software stacks.
Jul 21, 2026

Pillar Security's 'Week of Sandbox Escapes' shows AI coding agents escaping confinement not by breaking walls, but by writing files that trusted tools outside the sandbox execute later.
Jul 21, 2026
