BleepingComputer's Ax Sharma reported September 20, 2026 that Accomplish AI researcher Oren Yomtov reported two Codex sandbox escapes to OpenAI on August 12 and that both were fixed within eight days, that Heapjack targets Codex Desktop's node_repl written into global ~/.codex/config.toml with a shared V8 heap that can yield a stolen token and read-only-mode remote code execution when a user opens a hostile repository and asks a question, producing unsandboxed host commands with no approval prompt, that Overpatch sits in Codex CLI workspace-write mode where apply_patch can widen write permission via a /tmp path toward root and can append to .zshrc via symlink, that OpenAI fixed Heapjack in Codex Desktop build 26.818.21641 and Overpatch in Codex CLI 0.149.0, and that OpenAI told BleepingComputer it thanked the researchers, addressed the issues in August, and is continually strengthening sandboxes. Cyber Security News and Fudzilla framed the same Heapjack and Overpatch pair as distinct from the earlier Plugin4Shell story already covered in a prior batch. Those are unfinished Codex sandbox-escape patch facts plus unfinished update-adoption clock facts. They are not proof every Codex user is already owned forever, and they are not proof AI coding agents are already proven unfixable forever.
That is an unfinished Codex sandbox-escape patch layered on unfinished update-adoption clocks. It is not a finished every-Codex-user-already-owned-forever certificate, and it is not a finished AI-coding-agents-proven-unfixable-forever certificate.
## What They Reported
BleepingComputer framed Yomtov's August 12 report, the eight-day fix window, Heapjack's node_repl and shared-heap token theft path to unsandboxed host commands from read-only mode after opening a hostile repo, Overpatch's apply_patch write widening via /tmp toward root and symlink .zshrc risk, Desktop build 26.818.21641 and CLI 0.149.0 as the fixes, and OpenAI's statement thanking researchers while saying the issues were addressed in August with ongoing sandbox hardening. Cyber Security News repeated the Heapjack and Overpatch mechanics and fix versions. Fudzilla stressed two escape hatches, the hostile-repo question path, and the update call. Named journalism published unfinished patched escapes and unfinished update-adoption facts. It did not publish that every Codex user was already owned forever or that AI coding agents were already proven unfixable forever.
Security feeds often compress "sandbox escape" plus "unsandboxed host commands" into "every Codex user already owned forever," or compress "two escape hatches" into "AI coding agents already proven unfixable forever." Both habits flatten what BleepingComputer, Cyber Security News, and Fudzilla published: unfinished Codex sandbox-escape patches plus unfinished update-adoption clocks, not finished forever universal ownership and not finished forever unfixability.
## The Correction
Three corrections are required at once.
First, treating Heapjack's read-only-mode RCE path and Overpatch's write-widening path as proof every Codex user is already owned forever invents finished forever universal compromise from unfinished patched flaws. Yomtov's report date, the eight-day remediation, Desktop build 26.818.21641, and CLI 0.149.0 are unfinished patch-and-version facts, not every Codex user already owned forever.
Second, treating two named escapes and similar trust-boundary problems across AI coding agents as proof AI coding agents are already proven unfixable forever invents finished forever unfixability from unfinished engineering debt. OpenAI's statement that the issues were addressed in August and that sandboxes are continually being strengthened is unfinished hardening language, not AI coding agents already proven unfixable forever. Unfinished patch clocks are not already AI coding agents proven unfixable forever, and unfinished patch clocks are not already every Codex user already owned forever.
Third, treating update-adoption uncertainty, the global ~/.codex/config.toml inheritance for CLI users, and the hostile-repo question trigger as proof either that every Codex user is already owned forever or that AI coding agents are already proven unfixable forever invents finished end-states from unfinished adoption clocks. Users who have not yet updated sit on an unfinished adoption clock, not on finished forever universal ownership, and not on finished forever unfixability. This story is Heapjack and Overpatch, not the earlier Plugin4Shell item.
Accurate language therefore holds three layers apart. Layer one: September 20, 2026 BleepingComputer (Ax Sharma), Cyber Security News, and Fudzilla reported that Oren Yomtov of Accomplish AI disclosed two Codex sandbox escapes fixed within eight days of an August 12 report. Layer two: Heapjack - Codex Desktop node_repl in global ~/.codex/config.toml; shared V8 heap; stolen token; read-only mode RCE via hostile repo plus question; unsandboxed host commands; no approval prompt; fixed in Desktop build 26.818.21641; Overpatch - Codex CLI workspace-write; apply_patch widens write via /tmp path toward root; .zshrc via symlink; fixed in CLI 0.149.0; OpenAI thanked researchers, said addressed in August, continually strengthening sandboxes; distinct from prior Plugin4Shell coverage. Layer three: unfinished Codex sandbox-escape patches plus unfinished update-adoption clocks is not already every Codex user already owned forever and not already AI coding agents proven unfixable forever.
## Why This Matters
AI-agent security headlines overreact because "sandbox escape" and "unsandboxed host commands" travel faster than the difference between an unfinished patched flaw and every Codex user already owned forever, and faster than unfinished update-adoption clocks versus AI coding agents already proven unfixable forever.
False already-every-user-owned claims confuse developers about still-shipped Desktop and CLI fixes and still-live update status on their machines. False already-proven-unfixable claims erase the eight-day remediation and OpenAI's stated August fixes. Accurate coverage can report real Heapjack and Overpatch escapes without converting unfinished patches and adoption clocks into finished forever catastrophe theater.
NewsCorrections technology rule: unfinished Codex sandbox-escape patches and unfinished update-adoption clocks are not already every Codex user already owned forever and not already AI coding agents proven unfixable forever.
## Key Takeaways
- September 20, 2026: BleepingComputer (Ax Sharma), Cyber Security News, and Fudzilla reported Accomplish AI researcher Oren Yomtov's two Codex sandbox escapes, reported to OpenAI August 12 and fixed within eight days. - Heapjack: Codex Desktop node_repl in global ~/.codex/config.toml; shared V8 heap; stolen token; read-only mode RCE after opening a hostile repo and asking a question; unsandboxed host commands; no approval prompt; fixed in Desktop build 26.818.21641. - Overpatch: Codex CLI workspace-write; apply_patch widens write via /tmp path toward root; .zshrc via symlink; fixed in CLI 0.149.0; OpenAI thanked researchers and said issues were addressed in August while continually strengthening sandboxes. - Unfinished Codex sandbox-escape patches plus unfinished update-adoption clocks is not already every Codex user already owned forever and not already AI coding agents proven unfixable forever. - Follow later update adoption and sandbox hardening - not already-every-user-owned or already-agents-unfixable memes.

