Researchers found that .env files inside cloned repositories could be used to change the Codex CLI home directory path and ...
OpenAI patched a command injection flaw in its Codex CLI tool that let attackers run arbitrary commands on developer machines ...
The cause appears to be the use of non-ASCII characters in file names. Microsoft describes it like so: “Any user may be ...