Home

Description

OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.

PUBLISHED Reserved 2025-07-25 | Published 2025-07-25 | Updated 2025-07-25 | Assigner mitre




MEDIUM: 4.1CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-829 Inclusion of Functionality from Untrusted Control Sphere

Product status

Default status
unaffected

Any version before 0.9.0
affected

References

github.com/openai/codex/pull/1644

github.com/openai/codex/compare/rust-v0.8.0...rust-v0.9.0

github.com/...ommit/6cf4b96f9dbbef8a94acc1ff703eb118481514d8

cve.org (CVE-2025-54558)

nvd.nist.gov (CVE-2025-54558)

Download JSON