codexGHSA-xrxf-jgv3-qmrm
OpenAI Codex CLI enables code execution through malicious MCP (Model Context Protocol) configuration files
Critical9.8CVE-2025-61260 · Published Apr 14, 2026 · updated Apr 16, 2026
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers to embed arbitrary commands that execute immediately.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| @openai/codex npm | <= 0.23.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2025-61260
More codex advisories
All codex| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 192025 | Codex has sandbox bypass due to bug in path configuration logic | High | 0.39.0 |