Security researchers discovered two sandbox escape vulnerabilities in OpenAI's Codex coding agent. The more critical flaw, called Heapjack, allows remote code execution on a developer's machine by exploiting shared memory between trusted and untrusted JavaScript contexts. Both vulnerabilities were reported to OpenAI in August and patched within eight days.