CVE-2025-59532General

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandbox’s writable root, including paths outside of the folder where the user started their session. This logic bypassed the intended workspace boundary and enables arbitrary file writes and command execution where the Codex process has permissions - this did not impact the network-disabled sandbox restriction. This issue has been patched in Codex CLI 0.39.0 that canonicalizes and validates that the boundary used for sandbox policy is based on where the user started the session, and not the one generated by the model. Users running 0.38.0 or earlier should update immediately via their package manager or by reinstalling the latest Codex CLI to ensure sandbox boundaries are enforced. If using the Codex IDE extension, users should immediately update to 0.4.12 for a fix of the sandbox issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-28: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-28: 104-2404-2505-28
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-241
General1
2026-04-251
General1
2026-05-281
Patch1
Full discourse3 posts
  • Nicolas Krassas@Dinosn
    General

    Cohere Terrarium (CVE-2026-5752) and OpenAI Codex CLI (CVE-2025-59532): a cross-CVE analysis of AI code sandbox escapes https://blog.barrack.ai/pyodide-sandbox-escape-cohere-terrarium-openai-codex/

    Post summary

    The post references two sandbox escape CVEs and links to a blog that analyzes them, but it provides no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    1001022.2K
    158.1K followersView on X
  • /r/netsec@_r_netsec
    General

    Cohere Terrarium (CVE-2026-5752) and OpenAI Codex CLI (CVE-2025-59532): a cross-CVE analysis of AI code sandbox escapes https://blog.barrack.ai/pyodide-sandbox-escape-cohere-terrarium-openai-codex/

    Post summary

    A blog post links to a cross‑CVE analysis of sandbox escape vulnerabilities in Cohere Terrarium (CVE‑2026‑5752) and OpenAI Codex CLI (CVE‑2025‑59532), but provides no PoC, exploitation evidence, patch details, or in‑depth technical data.

    030311.3K
    33.4K followersView on X
  • 諏訪真一 / IT部門のジェネラリスト@suwa_sh
    Patch

    [5/] 最低ラインは v0.39.0 以降に固定。 sandbox writable root を奪われる CVE-2025-59532 と、CODEX_HOME 上書きで MCP が無承認起動する CVE-2025-61260。 両方の修正を含むのが v0.39.0 だからです。

    Post summary

    The post specifies that version v0.39.0 fixes CVE-2025-59532 (sandbox writable root) and CVE-2025-61260 (CODEX_HOME overwrite leading to unauthorized startup).

    1000069
    480 followersView on X

Explore more