CVE-2025-61260Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers to embed arbitrary commands that execute immediately.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 6d ago at 2 mentions (2026-04-19); latest day: 1
  • 9 total mentions across 8 days

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-04-18: 1Mentions · 2026-04-19: 2Mentions · 2026-04-28: 1Mentions · 2026-05-28: 1Mentions · 2026-08-04: 1Mentions · 2026-08-07: 1Mentions · 2026-08-15: 1Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-04: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 2Technical Details · 2026-04-28: 1Technical Details · 2026-08-15: 104-1804-1904-2805-2808-0408-0708-1508-21
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
PoC
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-181
Disclosure1
2026-04-192
Disclosure2
2026-04-281
Disclosure1
2026-05-281
Patch1
2026-08-041
PoC1
2026-08-071
Patch1
2026-08-151
Disclosure1
2026-08-211
Patch1
Full discourse9 posts
  • Kevin Kaminski@kkaminsk
    Patch

    2️⃣ The MCP 2026-07-28 spec is now the stable standard: paginated tool discovery, multi-round requests, non-blocking server startup. Plus: project trust gates address CVE-2025-61260, secrets redaction hides API keys in logs, and `--full-auto` is formally removed.

    Post summary

    The MCP 2026‑07‑28 spec update announces new features and that project trust gates address CVE‑2025‑61260, indicating a patch/mitigation rather than a PoC or exploit detail.

    1000054
    1.6K followersView on X
  • 諏訪真一 / IT部門のジェネラリスト@suwa_sh
    Disclosure

    現在進行形のリスクとして CVE-2025-61260 があります。CVSS 9.8、Codex CLI v0.23.0 以下が影響。信頼できないリポジトリの config を確認なしに読み込みます。 まず codex --version を確認してください。

    Post summary

    CVE‑2025‑61260 is a high‑severity flaw in Codex CLI v0.23.0 and earlier, permitting untrusted repository configurations to be loaded without user confirmation.

    1000068
    496 followersView on X
  • Kevin Kaminski@kkaminsk
    Patch

    2️⃣ MCP 2026-07-28 spec finalized — paginated tool discovery, multi-round requests, non-blocking server startup. Backward compatible. Opt in via protocol_version in config.toml. Plus: project trust gates (addresses CVE-2025-61260) and secrets redaction in CLI output.

    Post summary

    The MCP spec update announces a fix for CVE‑2025‑61260 through project trust gates and includes new features, but does not provide vulnerability details or exploit information.

    1000077
    1.6K followersView on X
  • 諏訪真一 / IT部門のジェネラリスト@suwa_sh
    Patch

    [5/] 最低ラインは v0.39.0 以降に固定。 sandbox writable root を奪われる CVE-2025-59532 と、CODEX_HOME 上書きで MCP が無承認起動する CVE-2025-61260。 両方の修正を含むのが v0.39.0 だからです。

    Post summary

    The post announces that version v0.39.0 contains fixes for CVE‑2025‑59532 and CVE‑2025‑61260, but offers no details on the vulnerabilities or exploits.

    1000069
    480 followersView on X
  • Yaniv Radunsky@hasamba
    Disclosure

    Check Point research: Claude Code, OpenAI Codex and Cursor can execute commands from benign-looking config files (CVE-2025-59536, CVE-2025-61260, CVE-2025-54136). Key vectors: lifecycle hooks, .env overrides, plugin-name trust. #AIsecurity #CVE https://www.geektime.co.il/ai-agent-config-files-attack-vector/

    Post summary

    Check Point research discloses that certain AI models can execute commands via config files, detailing vectors while denying evidence of exploitation or remediation.

    00010706
    698 followersView on X
  • 諏訪真一 / IT部門のジェネラリスト@suwa_sh
    PoC

    なので当面は「設計リファレンス + 限定PoC」として読むのが妥当だと整理しました。 CVE-2025-61260(CLI v0.23以下)や監査ログ30日の死角もあります。職種別の導入境界をどう設計するか、まとめています。 あなたの組織は、Codex 拡張をこのまま全面導入する側でしょうか。それとも設計リファレンスとして読む側でしょうか。 https://suwa-sh.github.io/zenn-contents/articles/codex-for-every-role_20260604/

    Post summary

    The text references CVE‑2025‑61260, mentions a limited PoC, and offers a design reference for Codex deployment, but it lacks exploitation details or patch information.

    0000069
    495 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-61260 A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. … https://www.cve.org/CVERecord?id=CVE-2025-61260

    Post summary

    The post briefly announces CVE-2025-61260, identifying a remote code execution issue in OpenAI Codex CLI caused by malicious configuration files, with no PoC, exploit, or patch details provided.

    00000176
    57.2K followersView on X
  • タカミ|製造業の営業企画×広報@eigyo_koho_mfg
    Disclosure

    AIが「一緒に働く」時代、ちゃんと怖さも知っておきたい。 OpenAIのCodex CLIに脆弱性(CVE-2025-61260)が見つかった。悪意あるリポジトリを開いただけで、設定ファイルが自動ロードされ、任意コードが実行されてしまうかもしれない、という話。 AIエージェントが自律的に動くってことは、裏を返せば「誰かが仕込んだ罠も自律的に踏む」ということ。便利さと危うさは同じコインの表裏だ。 実務でできる対策はシンプル。(1)知らないリポジトリでエージェントを走らせない。(2)フォルダ権限を最小化する。(3)社内で安全な設定テンプレを共有する。 製造業の現場でもAIを使い始めているなら、この「権限の設計」こそが最初の仕事。ツールを賢く使うより、ツールに賢く使われない仕組みを先に作る。それが本当の意味でのAI活用だと思う。 https://advisories.gitlab.com/npm/%40openai/codex/CVE-2025-61260/ #AIエージェント

    Post summary

    The article announces CVE‑2025‑61260 in OpenAI Codex CLI, noting it could enable arbitrary code execution via automatically loaded configuration files from untrusted repositories; no exploitation evidence or patch information is provided.

    00000391
    29 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A code execution vulnerability (CVE-2025-61260) affects `OpenAI Codex CLI` through malicious `MCP` configurations. Exercise caution with untrusted files. #OpenAICodex #CLI #CodeExecution #infosec https://www.pulsepatch.io/posts/cve-2025-61260-openai-codex-cli-code-execution

    Post summary

    A new code execution flaw (CVE-2025-61260) in OpenAI Codex CLI via malicious MCP configurations is disclosed, with no PoC, exploit, patch, or active exploitation details shared.

    00000589
    12 followersView on X

Explore more