Researchers escape OpenAI Codex sandbox to run commands on host
Posted by PrivacyWire
A sandbox escape can turn code that should be isolated into commands running on a developer’s machine, exposing local files, credentials, and other private data. This shows why security tools must be judged by their real isolation boundaries, not only by their locked-down modes or stated protections. Have you encountered similar failures where an isolated tool could reach more of your system than expected?