{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0443",
  "aliases": [],
  "published": "2026-09-15T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Codex Desktop before build 26.818.21641, running in read-only mode, let untrusted code use a token in the shared process heap to reach unsandboxed command execution.",
  "details": "## What\n\nAccomplish reported Heapjack in the JavaScript tool installed by Codex Desktop. The sandbox remained active, but an authentication token in shared memory was accessible to untrusted code and could be used to reach unsandboxed command execution even in read-only mode.\n\n## Detection\n\nAccomplish reported a proof of concept and says Codex Desktop build 26.818.21641 closes Heapjack.\n\n## Fix\n\nUpgrade Codex Desktop to build 26.818.21641 or later.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "codex-desktop"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "26.818.21641"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "sandbox-escape",
        "credential-exposure",
        "command-injection"
      ],
      "cwe": [
        "CWE-522",
        "CWE-693"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI05",
          "ASI03"
        ],
        "atlas": [
          "AML.T0105"
        ]
      },
      "cveBoundary": "pending-cve",
      "noCveReason": "No CVE was assigned in the public disclosure.",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Upgrade Codex Desktop to build 26.818.21641 or later.",
        "actions": [
          {
            "type": "upgrade",
            "target": "harness:codex-desktop",
            "to": "26.818.21641",
            "why": "The report identifies this as the Heapjack fix.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Codex Desktop before build 26.818.21641",
          "any": false,
          "status": "detected",
          "source": "https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any task run in Codex Desktop read-only mode",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "The Codex Desktop JavaScript tool, shared process heap and read-only sandbox",
          "status": "confirmed",
          "source": "https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/"
        },
        "approval": {
          "value": "The token path ran in read-only mode without an approval prompt",
          "mode": "sandbox-escape",
          "status": "detected",
          "source": "https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/"
        },
        "inputControl": "repo-author",
        "agentAction": "Untrusted code uses the shared token to reach command execution outside the sandbox.",
        "harm": "arbitrary-command",
        "divergence": "none",
        "reach": {
          "value": "The host process and its unsandboxed command execution",
          "kinds": [
            "home-directory",
            "network"
          ],
          "status": "detected",
          "source": "https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/"
        }
      },
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
