Index › ai › codex codex 1 tool · 1 release line OpenAI's agentic coding CLI. Every tool here carries the same sandbox boundary. $ boks codex ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 0.149.1 stable 2026-08-25 23 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ codex browsernetnomountrw default H13M9L1 codex OpenAI's agentic coding CLI ▸ showing codex from codex@latest → 0.149.1 stable Findings H13M9L1 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GHSA-3v94-mw7p-v465 ↗ H 8.7 hickory-proto hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses GHSA-x494-mj8g-cj27 ↗ H 8.7 gix-pack gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data GHSA-xp3w-r5p5-63rr ↗ H 8.7 openssl rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs GHSA-hppc-g8h3-xhp3 ↗ H 8.3 openssl rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer GHSA-ghm9-cr32-g9qj ↗ H 8.1 openssl rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check GHSA-f26g-jm89-4g65 ↗ H 7.8 gix gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules GHSA-f89h-2fjh-2r9q ↗ H 7.8 gix-fs gix-fs: Symlink prefix-reuse allows worktree escape during checkout GHSA-fr8x-3vfx-f45h ↗ H 7.7 gix gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository GHSA-pg4w-g64p-qwhj ↗ H 7.7 gix gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository GHSA-4w2j-m93h-cj5j ↗ H 7.5 quinn-proto Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly GHSA-p3hw-mv63-rf9w ↗ H 7.5 gix gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure GHSA-8c75-8mhr-p7r9 ↗ H 7.2 openssl rust-openssl has incorrect bounds assertion in aes key wrap GHSA-pqf5-4pqq-29f5 ↗ H 7.2 openssl rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 GHSA-q2qq-hmj6-3wpp ↗ M 6.9 hickory-proto hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression GHSA-xhj4-vrgc-hr34 ↗ M 6.3 actix-http actix-http has HTTP/1.1 CL.TE Request Smuggling GHSA-3rjw-m598-pq24 ↗ M 5.5 cmov Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set GHSA-h395-gr6q-cpjc ↗ M 5.5 jsonwebtoken jsonwebtoken has Type Confusion that leads to potential authorization bypass GHSA-w9wp-h8wv-79jx ↗ M 5.3 opentelemetry_sdk opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation GHSA-7gcf-g7xr-8hxj ↗ M 5.1 serde_with serde_with: KeyValueMap serialization panics on empty sequence or map entries GHSA-phqj-4mhp-q6mq ↗ M 5.1 openssl rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers GHSA-xv59-967r-8726 ↗ M 5.1 openssl rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding GHSA-xmgf-hq76-4vx2 ↗ L 1.7 openssl rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length GHSA-3pv8-6f4r-ffg2 ↗ M — tar tar has a PAX header desynchronization issue These are the findings of codex, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding. Composition default + bash, coreutils, diffutils, env, findutils, git, grep, rg, sed runtime none — self-contained composes bash, coreutils, diffutils, env, findutils, git, grep, rg, sed Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/boks-sh/codex:0.149.1 digest sha256:f939…38f1 copy platforms amd64 sha256:8fbb…490e copy arm64 sha256:7096…a10e copy size 258 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-25 Sandbox boundary codex capabilities browsernetnomountrw Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.codex · writable env passed through 13 forwarded CODEX_ACCESS_TOKENCODEX_API_KEYHTTPS_PROXYHTTP_PROXYNO_PROXYOPENAI_API_KEYOPENAI_BASE_URLOPENAI_ORGANIZATIONOPENAI_PROJECTTERM_PROGRAMhttp_proxyhttps_proxyno_proxy Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks none none per-subcommand grants differ completion + nomount − browsernetrw Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Where it needs less, boks takes it away there too. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-25 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 23 findings across this project at latest. Counted once per advisory across every image the project builds.