OpenAI Codex CLI MCP Configuration Remote Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

A critical vulnerability exists in OpenAI Codex CLI that allows arbitrary command execution when a user opens a malicious repository. The Model Context Protocol (MCP) server configuration can be defined through a project-level .codex/config.toml file within an untrusted workspace.

Timeline

Discovered on
January 19, 2026
Disclosed to Vendor on
January 19, 2026
Published on
January 20, 2026

Credit

Blog Post

References

Learn how Mindgard can help you navigate AI Security

Take the first step towards securing your AI. Book a demo now and we'll reach out to you.