Security fixes are made against the latest version on the default branch.
Please do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting feature on this repository:
- Open the repository's Security tab.
- Choose Advisories.
- Select Report a vulnerability.
Include reproduction steps, affected versions, impact, and any suggested mitigation. Do not attach Codex transcripts, rollout files, credentials, or other private user data.
You should receive an initial response within seven days. A fix and disclosure timeline will be coordinated based on severity and complexity.
Particularly useful reports include:
- unintended writes to Codex state or configuration;
- credential or transcript exposure;
- unsafe command construction or arbitrary command execution;
- failure of push-to-talk key-release safeguards;
- actions operating on a different chat than the one shown;
- network communication that contradicts the documented local-only design.