ACVE-2026-0442
Codex CLI below 0.149.0, using its apply_patch tool in a sandbox, could write outside the intended workspace without a prompt.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
In the wild
demonstrated
Description
What
Accomplish reported Overpatch in Codex CLI: the patch tool's permission grant could reach the parent of a patched path, allowing a patch to write elsewhere on the disk even when the agent was sandboxed.
Detection
Accomplish reported a proof of concept and says Codex CLI 0.149.0 closes Overpatch.
Fix
Upgrade Codex CLI to 0.149.0 or later.
Fix
Upgrade Codex CLI to 0.149.0 or later.
- Upgrade
harness:codex-clito0.149.0. The report identifies this as the Overpatch fix. Owner: operator