{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0554",
  "aliases": [],
  "published": "2026-07-13T00:00:00Z",
  "firstReported": {
    "date": "2026-07-13",
    "url": "https://x.com/brunolemos/status/2076769881534398974",
    "publisher": "Bruno Lemos"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Codex with GPT-5.6 Sol, in auto-review mode, ran destructive tests against a production Neon database whose URL sat in the repo's .env, emptying its tables; no restore has been reported.",
  "details": "## What\n\nBruno Lemos had a Codex goal to finish implementing a small side project running for more than 14 hours, and asked the agent only to create a small seed of data so he could test the app locally. It did that, then after running the end-to-end tests decided to clean up on its own. The repository's .env held the Neon production DATABASE_URL. In its own post-mortem, which he posted, the agent says it pointed TEST_DATABASE_URL at that production URL instead of provisioning a disposable local test database, and because PRODUCTION_DATABASE_URL was unset it did not recognise the URL as production. The integration tests ran TRUNCATE statements and left the production tables empty. The session used GPT-5.6 Sol at Extra High reasoning effort with Codex's \"Approve for me\" auto-review, which asks only for actions it detects as potentially unsafe; the tests were not stopped. The agent said recovery was likely still possible through Neon's restore window, but no post confirming a restore was found. The same coverage reported a $HOME deletion with a different mechanism, recorded as ACVE-2026-0518.\n\n## Detection\n\nThe lockfile records the Codex CLI version and approval mode, not the contents of .env. Recorded from the operator's posts on X and the Codex screenshots he published. Not recreated in a lab.\n\n## Fix\n\nKeep production credentials out of the environment an agent uses for tests, give tests a disposable database, and require approval for destructive database commands.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "codex-cli"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://x.com/brunolemos/status/2076769881534398974"
    },
    {
      "type": "EVIDENCE",
      "url": "https://pbs.twimg.com/media/HNIoIunWgAA7pI4.jpg?name=orig"
    },
    {
      "type": "REPORT",
      "url": "https://x.com/brunolemos/status/2076774663603052583"
    },
    {
      "type": "REPORT",
      "url": "https://x.com/brunolemos/status/2076808504346587433"
    },
    {
      "type": "EVIDENCE",
      "url": "https://pbs.twimg.com/media/HNJOU2aXUAAzu8Y.jpg?name=orig"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.theregister.com/ai-and-ml/2026/07/16/openai-admits-gpt-56-occasionally-deletes-files-but-its-an-honest-mistake/5274008"
    },
    {
      "type": "ARTICLE",
      "url": "https://techcrunch.com/2026/07/14/openais-new-flagship-model-deletes-files-on-its-own-people-keep-warning/"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "behavioural",
      "vulnClasses": [
        "over-privileged-combination",
        "credential-exposure"
      ],
      "cwe": [
        "CWE-693"
      ],
      "noCveReason": "No code defect: the harm arises from the agent pursuing its goal in this configuration.",
      "cveBoundary": "behavioural",
      "threat": {
        "attacker": "user",
        "vector": "unsafe-default",
        "outcome": "harmful-action"
      },
      "evidence": [
        {
          "kind": "incident",
          "url": "https://x.com/brunolemos/status/2076769881534398974"
        }
      ],
      "fix": {
        "summary": "Keep production credentials out of the agent's test environment; require approval for destructive database commands.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "agent.approval",
            "to": "ask",
            "why": "Auto-review let integration tests that truncate tables run against production without a prompt.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "env:DATABASE_URL",
            "to": "no production database URL in the environment the agent uses for tests",
            "why": "The repository's .env held the production DATABASE_URL, which the agent reused as the test database.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "openai.codex.autoReview",
            "to": "treats tests pointed at a non-local database as potentially unsafe",
            "why": "Recommended: auto-review let tests truncate the production tables without a prompt.",
            "owner": "harness-vendor"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Codex with the \"Approve for me\" permission setting (version not stated)",
          "any": false,
          "status": "confirmed",
          "source": "https://pbs.twimg.com/media/HNIoIunWgAA7pI4.jpg?name=orig"
        },
        "model": {
          "value": "GPT-5.6 Sol at Extra High reasoning effort",
          "any": false,
          "status": "confirmed",
          "source": "https://pbs.twimg.com/media/HNIoIunWgAA7pI4.jpg?name=orig"
        },
        "goal": {
          "value": "Create a small seed of data so the operator could test the app locally",
          "stated": true,
          "status": "confirmed",
          "source": "https://x.com/brunolemos/status/2076808504346587433"
        },
        "tools": {
          "value": "Shell access in a repository whose .env held the Neon production DATABASE_URL, and the project's integration and end-to-end tests",
          "status": "confirmed",
          "source": "https://pbs.twimg.com/media/HNJOU2aXUAAzu8Y.jpg?name=orig"
        },
        "approval": {
          "value": "\"Approve for me\" auto-review, which asks only for actions it detects as potentially unsafe; the destructive tests ran without a prompt",
          "mode": "auto-approve",
          "status": "confirmed",
          "source": "https://pbs.twimg.com/media/HNIoIunWgAA7pI4.jpg?name=orig"
        },
        "inputControl": "operator",
        "agentAction": "After the seed task, the agent cleans up on its own: it points its test database variable at the production database and runs integration tests that truncate the tables.",
        "harm": "data-loss",
        "divergence": "shortcut",
        "reach": {
          "value": "The project's production Neon database, reached through the DATABASE_URL in the repository's .env",
          "kinds": [
            "production-database"
          ],
          "status": "confirmed",
          "source": "https://pbs.twimg.com/media/HNJOU2aXUAAzu8Y.jpg?name=orig"
        },
        "condition": {
          "value": "When the agent pointed TEST_DATABASE_URL at the production Neon URL instead of provisioning a disposable test database, and with PRODUCTION_DATABASE_URL unset did not recognise it as production",
          "status": "confirmed",
          "source": "https://pbs.twimg.com/media/HNJOU2aXUAAzu8Y.jpg?name=orig"
        },
        "recovery": {
          "value": "Not reported: the agent said a restore was likely still possible through Neon's restore window, but no post confirms one.",
          "outcome": "unknown",
          "status": "unconfirmed"
        }
      },
      "occurrence": {
        "basis": "real-use",
        "reportedBy": "operator",
        "primary": [
          {
            "url": "https://x.com/brunolemos/status/2076769881534398974",
            "kind": "operator-account",
            "party": "Bruno Lemos (@brunolemos)"
          },
          {
            "url": "https://pbs.twimg.com/media/HNIoIunWgAA7pI4.jpg?name=orig",
            "kind": "agent-transcript",
            "party": "Codex session, published by Bruno Lemos"
          },
          {
            "url": "https://x.com/brunolemos/status/2076774663603052583",
            "kind": "operator-account",
            "party": "Bruno Lemos (@brunolemos)"
          },
          {
            "url": "https://x.com/brunolemos/status/2076808504346587433",
            "kind": "operator-account",
            "party": "Bruno Lemos (@brunolemos)"
          },
          {
            "url": "https://pbs.twimg.com/media/HNJOU2aXUAAzu8Y.jpg?name=orig",
            "kind": "agent-transcript",
            "party": "Codex session, published by Bruno Lemos"
          }
        ]
      },
      "exploitation": {
        "status": "none-known",
        "checkedAt": "2026-09-25T00:00:00Z",
        "sources": [
          {
            "url": "https://techcrunch.com/2026/07/14/openais-new-flagship-model-deletes-files-on-its-own-people-keep-warning/",
            "type": "news",
            "note": "operator account; no attacker"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "claims": [],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": true,
        "observableStated": true,
        "demonstrated": "reported-only",
        "missing": [
          "model availability not checked (no registry reference)"
        ]
      },
      "severityBasis": "harm-reach",
      "taxonomy": {
        "owasp_asi": [
          "ASI02",
          "ASI03"
        ]
      }
    }
  }
}
