Description
The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. The app automatically fetched that URL when rendering the response, sending the embedded data to an attacker-controlled server without a separate user click. Successful exploitation could exfiltrate secrets and other information accessible in the Codex session, including API keys, source code, and data returned by connected tools. No direct integrity or availability impact was demonstrated, and there is no known exploitation in the wild.
Published: 2026-07-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The OpenAI Codex desktop app for macOS renders images referenced in Markdown within model responses. Content processed by Codex, such as a connected‑tool result or other untrusted source, can induce the model to construct a remote image URL that includes sensitive data. The application automatically fetches that URL when rendering the response, sending the embedded data to an attacker‑controlled server without a user click. Successful exploitation could exfiltrate secrets and other information accessible in the Codex session, including API keys, source code, and data returned by connected tools. No direct integrity or availability impact has been demonstrated.

Affected Systems

OpenAI Codex desktop application for macOS in all releases prior to version 26.527.31326.

Risk and Exploitability

The EPSS score of < 1% suggests a very low probability of exploitation while the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates moderate severity. An attacker must first gain an indirect prompt injection foothold, typically by providing untrusted content that Codex processes. If successful, the app will fetch the malicious image and transmit the payload to a remote server, resulting in the exfiltration of sensitive session data. No real‑world exploitation evidence is currently available, but the combination of a feasible exploitation path and the potential for data leakage presents a significant confidentiality risk.

Generated by OpenCVE AI on July 23, 2026 at 14:31 UTC.

Remediation

Vendor Solution

Upgrade to 26.527.31326 or later. The product fix disables loading remote images from Markdown.


Vendor Workaround

If an upgrade is not possible, avoid processing untrusted content and connected-tool data in affected versions.


OpenCVE Recommended Actions

  • Upgrade the Codex desktop app to version 26.527.31326 or newer, which disables remote image loading from Markdown.
  • If upgrading is delayed, avoid processing untrusted content and connected‑tool data in affected versions.
  • If upgrading is delayed, refrain from using Markdown that references remote images until the application is patched.

Generated by OpenCVE AI on July 23, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://openai.com/codex/ cve-icon
History

Thu, 23 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remote Image Loading Exposes Sensitive Data in OpenAI Codex Desktop App

Tue, 21 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Remote Image Loading Exposes Sensitive Data in OpenAI Codex Desktop App

Fri, 17 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote image loading allows exfiltration of sensitive session data in OpenAI Codex desktop app

Wed, 15 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote image loading allows exfiltration of sensitive session data in OpenAI Codex desktop app

Tue, 14 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Exfiltration of Sensitive Data via Remote Image Loading from Untrusted Markdown in Codex Desktop

Mon, 13 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Exfiltration of Sensitive Data via Remote Image Loading from Untrusted Markdown in Codex Desktop

Sun, 12 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Exfiltration of Sensitive Data via Remote Image Loading in OpenAI Codex Desktop App

Fri, 10 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Exfiltration of Sensitive Data via Remote Image Loading in OpenAI Codex Desktop App

Fri, 10 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Remote image loading in Codex desktop leads to data exfiltration

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote image loading in Codex desktop leads to data exfiltration

Wed, 08 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Remote Image Loading Enables Data Exfiltration in OpenAI Codex Desktop App

Wed, 08 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Remote Image Loading Enables Data Exfiltration in OpenAI Codex Desktop App

Tue, 07 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Exfiltration via Remote Image Loading in OpenAI Codex Desktop App

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Exfiltration via Remote Image Loading in OpenAI Codex Desktop App

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Openai
Openai codex Desktop App For Macos
Vendors & Products Openai
Openai codex Desktop App For Macos

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. The app automatically fetched that URL when rendering the response, sending the embedded data to an attacker-controlled server without a separate user click. Successful exploitation could exfiltrate secrets and other information accessible in the Codex session, including API keys, source code, and data returned by connected tools. No direct integrity or availability impact was demonstrated, and there is no known exploitation in the wild.
Weaknesses CWE-200
References

Subscriptions

Openai Codex Desktop App For Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: OAI

Published:

Updated: 2026-07-07T15:35:14.109Z

Reserved: 2026-07-06T19:35:48.882Z

Link: CVE-2026-14898

cve-icon Vulnrichment

Updated: 2026-07-07T15:35:04.182Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T14:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor