← Back to browse · API

CVE-2025-61260

Severity
CRITICAL
CVSS
9.8
EPSS
0.06583
Risk score
41.5
CISA KEV
No
PoC
No
Published
2026-04-14
Modified
2026-07-05
First seen
2026-08-07
Aliases
EUVD-2025-209435, GHSA-XRXF-JGV3-QMRM
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-209435

Description

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and .codex/config.toml files without requiring user confirmation, allowing attackers to embed arbitrary commands that execute immediately.

References