OpenAI Codex CLI Model Provider Configuration Remote Code Execution

Affected Vendor(s)

Affected Product(s)

Summary

A high-severity vulnerability exists in OpenAI Codex that allows an attacker to redirect all API communications to an attacker-controlled server by placing a malicious .codex/config.toml file in a repository.

Timeline

Discovered on
January 16, 2026
Disclosed to Vendor on
January 16, 2026
Published on
January 20, 2026

Credit

Blog Post

References