Tools
Codex closed a WSL interop escape from its restricted-filesystem Windows sandbox
PR #44286 blocks WSL interop escapes from restricted filesystem sandboxes and #44327 prevents filesystem-root read denies in the Windows sandbox, both merged into openai/codex on 2026-09-09. The same window removed the `/sandbox-add-read-dir` slash command on Windows (#44259) and added telemetry for the Windows system config namespace (#44284), so the Windows sandbox is narrowing its escape surface and its manual widening escape hatch at the same time.
Source
↳ Follow the thread