Impact
codex_mcp contains a function in src/codex-process-simple.ts that permits a local attacker to manipulate the argument model and execute arbitrary system commands, leading to command injection. This flaw maps to CWE‑74 and CWE‑77 and could allow a local user to gain elevated privileges or compromise the host if they can invoke the affected function.
Affected Systems
The affected product is codex_mcp by the vendor andreahaku. Because the project does not use semantic versioning and no release information is available, any deployment containing the code prior to the commitment of the fix is likely affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available, so the overall likelihood of exploitation appears low to moderate. The vulnerability requires a local attack vector, meaning the attacker must have local access to the system; it is not remotely exploitable. The lack of a CISA KEV listing suggests that no publicly known exploit currently targets this weak point, but future internal or credential‑based actors could still leverage it.
OpenCVE Enrichment