Kevin Kaminski[verified]@kkaminskPatch
The MCP 2026‑07‑28 spec update announces new features and that project trust gates address CVE‑2025‑61260, indicating a patch/mitigation rather than a PoC or exploit detail.
諏訪真一 / IT部門のジェネラリスト[verified]@suwa_shDisclosure
CVE‑2025‑61260 is a high‑severity flaw in Codex CLI v0.23.0 and earlier, permitting untrusted repository configurations to be loaded without user confirmation.
Kevin Kaminski[verified]@kkaminskPatch
The MCP spec update announces a fix for CVE‑2025‑61260 through project trust gates and includes new features, but does not provide vulnerability details or exploit information.
諏訪真一 / IT部門のジェネラリスト[verified]@suwa_shPatch
The post announces that version v0.39.0 contains fixes for CVE‑2025‑59532 and CVE‑2025‑61260, but offers no details on the vulnerabilities or exploits.
諏訪真一 / IT部門のジェネラリスト[verified]@suwa_shPoC
The text references CVE‑2025‑61260, mentions a limited PoC, and offers a design reference for Codex deployment, but it lacks exploitation details or patch information.
タカミ|製造業の営業企画×広報[verified]@eigyo_koho_mfgDisclosure
The article announces CVE‑2025‑61260 in OpenAI Codex CLI, noting it could enable arbitrary code execution via automatically loaded configuration files from untrusted repositories; no exploitation evidence or patch information is provided.
Yaniv Radunsky@hasambaDisclosure
Check Point research discloses that certain AI models can execute commands via config files, detailing vectors while denying evidence of exploitation or remediation.
CVE@CVEnewDisclosure
The post briefly announces CVE-2025-61260, identifying a remote code execution issue in OpenAI Codex CLI caused by malicious configuration files, with no PoC, exploit, or patch details provided.