OpenAI launched the release of Codex Security on Friday, a security agent with artificial intelligence (AI) designed to detect, validate, and propose solutions for vulnerabilities.
See also: OpenAI: ChatGPT Upgrade with GPT-5.4 Thinking

The feature is available in research preview for ChatGPT Pro, Enterprise, Business and Edu customers via Codex web with free use for the next month.
“It creates deep context for your work to identify complex vulnerabilities that other tools miss, highlighting high-confidence findings with solutions that substantially improve your system’s security while freeing you from the noise of trivial errors,” the company.
Codex Security represents an evolution of Aardvark, which OpenAI introduced in private beta in October 2025 as a way for developers and security teams to identify and fix security vulnerabilities at scale.
Over the past 30 days, Codex Security has scanned more than 1.2 million commits in external repositories during the beta, identifying 792 critical findings and 10,561 high severity findings. These include vulnerabilities in various open source projects such as OpenSSH, GnuTLS, GOGS, Thorium, libssh, PHP and Chromium, among others.
Some of these include:
- GnuPG – CVE-2026-24881, CVE-2026-24882 – GnuTLS – CVE-2025-32988, CVE-2025-32989 – GOGS – CVE-2025-64175, CVE-2026-25242 – Thorium – CVE-2025-35430, CVE-2025-35431, CVE-2025-35432, CVE-2025-35433, CVE-2025-35434, CVE-2025-35435, CVE-2025-35436
See also: OpenAI: $110 billion investment from Amazon, Nvidia & Softbank

According to the AI company, the latest version of the application security agent leverages the reasoning capabilities of its cutting‑edge models and combines them with automated validation to minimize the risk of false positives and provide actionable fixes.
OpenAI's scans of the same repositories over time have shown increasing accuracy and a reduction in false positives, with the latter decreasing by more than 50% across all repositories.
In a statement shared with The Hacker News, OpenAI said that Codex Security is designed to improve signal‑to‑noise, basing vulnerability discovery on the system's context and validating findings before presenting them to users.
Specifically, the agent operates in three steps: it analyzes a repository to understand the structure of the project related to security and creates an editable threat model that records what it does and where it is most exposed.
Once the system framework is created, Codex Security uses it as a basis for identifying vulnerabilities and classifies the findings based on their actual impact. The highlighted issues are tested in a sandbox environment to be validated.
The final stage involves the agent proposing solutions that align better with the system's behavior to reduce recurrences and make them easier to review and develop.
See also: OpenAI defeats xAI in trade secret lawsuit
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The news of Codex Security arrives weeks after the release of Claude Code Security by Anthropic to help users scan a software codebase for vulnerabilities and suggest fixes.
