GHSA-xrxf-jgv3-qmrm
CRITICALCVE-2025-61260A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers
- Affected
- <= 0.23.0
- Fixed in
- not stated
- Weakness
- CWE-94
- Published
- 2026-04-14
- Source
- github