OpenAI Codex CLI Vulnerable to Prompt Injection
A vulnerability chain in OpenAI Codex CLI for Windows abuses prompt injection through web.run to execute host-level commands outside the sandbox.
A vulnerability chain in OpenAI Codex CLI for Windows abuses prompt injection through web.run to execute host-level commands outside the sandbox.
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
GPT-5.4 achieved 100% compliance through Codex CLI, showing that this client environment is susceptible to the GhostSplice attack.