ACVEAgent configuration vulnerability registry

ACVE-2026-0443

Codex Desktop before build 26.818.21641, running in read-only mode, let untrusted code use a token in the shared process heap to reach unsandboxed command execution.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

In the wild

demonstrated

Description

What

Accomplish reported Heapjack in the JavaScript tool installed by Codex Desktop. The sandbox remained active, but an authentication token in shared memory was accessible to untrusted code and could be used to reach unsandboxed command execution even in read-only mode.

Detection

Accomplish reported a proof of concept and says Codex Desktop build 26.818.21641 closes Heapjack.

Fix

Upgrade Codex Desktop to build 26.818.21641 or later.

Fix

Upgrade Codex Desktop to build 26.818.21641 or later.

  • Upgrade harness:codex-desktop to 26.818.21641. The report identifies this as the Heapjack fix. Owner: operator

Report a problemJSON