Home

Description

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers to embed arbitrary commands that execute immediately.

PUBLISHED Reserved 2025-09-26 | Published 2026-04-14 | Updated 2026-04-16 | Assigner mitre

References

research.checkpoint.com/...-command-injection-vulnerability/ exploit

openai.com

research.checkpoint.com/...-command-injection-vulnerability/

cve.org (CVE-2025-61260)

nvd.nist.gov (CVE-2025-61260)

Download JSON