Finding / codex

2026-09-21-codex-sandbox-and-credential-hardening-no-advisories

Sandbox and credential hardening (no advisories). 0.152.0: cloud task requests reject untrusted backend URLs and disable redirects “to protect saved credentials”. 0.155.0: blocks Windows-process escapes from restricted WSL sandboxes, hardens brokered shell snapshots against credential exposure, and invalidates remote-control sessions and cached state on account switch. No GHSA or CVE was published for any of them.

Channel: tagged-release. Half: defect. Date: 2026-09-01..2026-09-17.

Operator consequence: Sandbox-escape and credential fixes are shipping as release-note bullets, not advisories. An advisory feed will not tell you to upgrade. On Windows/WSL, move to >=0.155.0. 0.156.0 (OUT) adds more isolation-gap fixes.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-codex-sandbox-and-credential-hardening-no-advisories

Profile citations

  • Codex / claim / hardening-without-advisories

Source links

Primary links, including exact changelog lines when available.