Home
MEDIUM: 4.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 0.9.0
affected
Description
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.
Problem types
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
Product status
Any version before 0.9.0
References
github.com/openai/codex/pull/1644
github.com/openai/codex/compare/rust-v0.8.0...rust-v0.9.0
github.com/...ommit/6cf4b96f9dbbef8a94acc1ff703eb118481514d8