Fetching from the wire…
Security2026-09-02 · source-backed
Published to NVD September 1, affecting Codex CLI on Windows, macOS and Linux plus Codex Desktop. The command-safety parser read PowerShell's stop-parsing token differently than PowerShell does, so commands got misclassified as safe. An attacker-prepared repository could get Codex to run a file-writing Git command without a prompt, overwrite Codex's own config, and have it launch an attacker-controlled MCP server on next load. Fixed in openai/codex PR #22643 by treating stop-parsing forms as unsupported in the AST-backed flattener. The default filesystem sandbox on macOS and Linux still limited writes, which is a decent argument for leaving it on.
Each link below shares sources, entities, or timing with this story.
Your read-only flag is a claim, not a guarantee. Two independent Postgres MCP servers proved it on September 4. Postgres MCP Pro got CVE-2026-85620 at CVSS 9.2. The bug is one line of reasoning in safe_sql.py: the validator checks function names on FuncCall AST nodes. A functi...
Roughly 245 commits, adding session forking, archive/restore from the TUI resume picker, full conversation export to Markdown or clipboard, and Amazon Bedrock Runtime as a built-in provider with AWS profile and region support. Hooks can now run commands asynchronously and invo...
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
CVE-2026-55546 at 9.8 sits in verify_math_expression() in QWED-MCP, described by its authors as "a deterministic verification gateway for MCP." It hands the attacker-controlled expression and claimed_result to parse_expr() after normalizing caret syntax, with no global_dict re...
The agent-security topic holds 42 repos above 100 stars, four from large companies rather than startups: NVIDIA/SkillSpector (14,498 stars, scanning Claude Code/Codex/MCP skills for prompt injection), Tencent/AI-Infra-Guard (4,467, red-teaming with Many-Shot/PAIR/GOAT/ActorAtt...
Tagged September 9 with isolated checkouts for new or forked sessions plus browse and resume across them. The release also lets you answer questions inline while Codex keeps working without losing your main draft, and gives Windows sessions a shared background Codex server wit...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.