Description
Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.
Problem types
CWE-61 UNIX Symbolic Link (Symlink) Following
Product status
References
research.jfrog.com/...ry-file-overwrite-jfsa-2025-001378631/
github.com/openai/codex/pull/1705