In a new example of how AI tools are expanding the attack surface of development engines, researchers have identified a serious RCE vulnerability in Codex CLI , one of the most popular coding agents powered by large language models (LLMs).
See also: OpenAI just made another circular deal

“This vulnerability allows silent, repetitive remote code execution in any environment where developers run codex in a repository,” said researchers at security firm CheckPoint, who discovered the vulnerability.
The vulnerability was reported to OpenAI and fixed in Codex CLI version 0.23.0 by preventing .env files from silently redirecting the CODEX _HOME environment variable to locations controlled by the attacker.
Like all AI-powered coding agents, Codex has some powerful privileges, as it must be able to read, edit, and execute code directly from the terminal. In default mode, the tool can perform tasks without approval within the working directory, but users can change this to either read-only mode or full access.
The tool's ability to execute commands and modify files in a controlled directory may not seem very dangerous at first glance, but CheckPoint researchers found a creative way to exploit it.
First, like many AI agents, Codex supports the Model Framework Protocol (MCP). Developed by AI company Anthropic, MCP has become the industry’s de facto method for connecting LLMs to external data sources and applications. In other words, it’s a building block for creating autonomous AI agents that can automatically discover and use third-party tools.
See also: OpenAI: Data breach via third-party provider Mixpanel

Codex CLI loads and runs configured MCP servers at startup by checking for mcp_servers entries in the configuration file .codex/config.toml. If an attacker can modify this file, they can force Codex to execute malicious commands by adding a malicious MCP server entry to the list.
Codex will look for its configuration file in its home directory, and this directory is set via an environment variable called CODEX_HOME. The researchers wondered if this variable could be bypassed when parsing .env files included in a repository, as including such files with projects is not uncommon.
The researchers found that a repository could have an .env file that sets CODEX_HOME to a path of the form ./.codex, essentially the .codex folder in the current working directory – the repository directory itself. Additionally, if the repository has a config.toml in the .codex directory, the Codex agent will treat it as its own configuration file and parse the mcp_servers.
The researchers demonstrated this attack by replacing innocent commands in MCP server logs with commands to create files or open a reverse shell on the machine. These commands were executed without user approval in the default configuration.
To exploit this vulnerability, the victim must clone the repository and run Codex on it, and an attacker must have commit access to the repository or have their malicious pull request accepted.
Furthermore, if continuous integration tools or build agents automatically run Codex on checked code, the breach could spread from a developer workstation to build objects and downstream deployments of the code.
See also: India: Apple asks to block antitrust law
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Organizations that allow their developers to work with AI coding agents and IDE tools should have policies regarding the level of automation with which these tools are configured, as they can easily become powerful backdoors in the event of vulnerabilities or misconfigurations. Security experts have repeatedly warned against using fully automated functions that do not require human review and approval of execution steps.
