Finding / codex
2026-09-21-codex-sandbox-and-credential-hardening-no-advisories
Sandbox and credential hardening (no advisories). 0.152.0: cloud task requests reject untrusted backend URLs and disable redirects “to protect saved credentials”. 0.155.0: blocks Windows-process escapes from restricted WSL sandboxes, hardens brokered shell snapshots against credential exposure, and invalidates remote-control sessions and cached state on account switch. No GHSA or CVE was published for any of them.
Channel: tagged-release. Half: defect. Date: 2026-09-01..2026-09-17.
Operator consequence: Sandbox-escape and credential fixes are shipping as release-note bullets, not advisories. An advisory feed will not tell you to upgrade. On Windows/WSL, move to >=0.155.0. 0.156.0 (OUT) adds more isolation-gap fixes.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-codex-sandbox-and-credential-hardening-no-advisories
Profile citations
- Codex / claim / hardening-without-advisories
Source links
Primary links, including exact changelog lines when available.