OpenAI Codex CLI/Desktop PowerShell Command-Safety Parser Bypass Leading to MCP Config Hijack
highAgentTool MisuseOpenAI Codex CLI and Desktop failed to correctly parse PowerShell's stop-parsing token (--%), causing malicious commands to be misclassified as safe and auto-approved. An attacker who gets a user to open a poisoned repository can trick Codex into running an unapproved file-writing Git command that rewrites Codex's own configuration, ultimately allowing it to launch an attacker-controlled MCP server and execute code with the user's privileges.
Updated Sep 4, 2026 · CVSS 8.8