Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-698g-97rr-xgjf

Опубликовано: 13 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

EPSS

Процентиль: 50%
0.00266
Низкий

8.8 High

CVSS3

Дефекты

CWE-61

Связанные уязвимости

CVSS3: 8.8
nvd
6 месяцев назад

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory.

EPSS

Процентиль: 50%
0.00266
Низкий

8.8 High

CVSS3

Дефекты

CWE-61