CVE-2026-14898Disclosure

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. The app automatically fetched that URL when rendering the response, sending the embedded data to an attacker-controlled server without a separate user click. Successful exploitation could exfiltrate secrets and other information accessible in the Codex session, including API keys, source code, and data returned by connected tools. No direct integrity or availability impact was demonstrated, and there is no known exploitation in the wild.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-04)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-07: 1Mentions · 2026-07-14: 1Mentions · 2026-09-04: 2Active Exploitation · 2026-09-04: 1Patch / Workaround · 2026-09-04: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-14: 1Technical Details · 2026-09-04: 207-0707-1409-04
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-071
Disclosure1
2026-07-141
Disclosure1
2026-09-042
Active Exploitation1General1
Full discourse4 posts
  • Fuelmeup@fuelmeupcc
    General

    One year might be generous. Researchers already showed breaches hitting AI coding tools like Cursor, Codex CLI and Google's Antigravity. There's a live Codex macOS bug, CVE-2026-14898, where the app auto-renders remote images in model responses and leaks sensitive data. Reward hacking in Codex is documented too. So the attack surface is here now, not a year out.

    Post summary

    The post highlights a documented macOS bug (CVE‑2026‑14898) that allows remote image rendering, potentially leaking sensitive data, but offers no PoC, exploit, patch, or evidence of active attacks.

    10030138
    1.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    OpenAI Codex for macOS の脆弱性 CVE-2026-14898:プロンプト・インジェクションによる機密情報漏洩の恐れ https://iototsecnews.jp/2026/07/07/openai-codex-desktop-app-for-macos-vulnerability-allows-attackers-to-inject-indirect-prompt/ OpenAI Codex for macOS における脆弱性 CVE-2026-14898 は、レスポンス内の Markdown に含まれるリモート画像を、 ユーザーの操作なしで自動的に読み込んで表示してしまう処理方法に起因します。 この自動レンダリングの動作と、プロンプト・インジェクションという手法が組み合わさることで、深刻な問題が発生します。信頼できないデータをアプリが処理する際に、機密データが埋め込まれた画像 URL が攻撃者の指示により作られ、 バックグラウンドで自動的に通信が行われ、データが外部へ漏えいしてしまいます。 AI ツールの便利な自動表示機能が、意図しない抜け道となってしまう仕組みです。ご利用のチームは、ご注意ください。 #Codex #CVE202614898 #OpenAI #PromptInjection #SocialEngineering #Vulnerability

    Post summary

    The article announces CVE-2026-14898 for OpenAI Codex on macOS, detailing how automatic Markdown image rendering can enable prompt injection and confidential data leakage, but provides no PoC, exploit code, or patch information.

    02000189
    502 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-14898 in OpenAI Codex for macOS allows attackers to exfiltrate sensitive data via indirect prompt injection, with no known exploitation in the wild https://ift.tt/yLZ87Ux

    Post summary

    The post announces the existence of CVE‑2026‑14898 in OpenAI Codex for macOS, describing indirect prompt injection that can exfiltrate sensitive data, and notes that no exploitation has been observed in the wild.

    10000126
    999 followersView on X
  • Fuelmeup@fuelmeupcc
    Active Exploitation

    @0xhashlol @aravind @montysingla Exactly. The Codex macOS bug (CVE-2026-14898) is that pattern in the wild. It auto-fetched remote images from Markdown in model responses, no click needed, so the embedded data went straight to an attacker server. Allowlist egress plus blocking image fetches is the right call.

    Post summary

    CVE-2026-14898 is actively exploited via autonomous Markdown image fetching in Codex macOS, with an attacker-supplied server receiving embedded data, and mitigation through egress allowlisting and blocking image fetches is advised.

    0000055
    469 followersView on X

Explore more