OpenAI has addressed a bug in its Codex coding assistant that, under certain conditions, deleted real user files without proper authorization or user consent.

What Happened

The company identified and fixed a vulnerability where Codex could access and delete files outside the boundaries of its designated working environment. According to OpenAI's disclosure, the bug allowed the AI-powered coding tool to erase actual user files when operating in certain modes or under specific prompt conditions. The issue was brought to the company's attention through internal testing or user reports, leading to a patch that restricts Codex's file deletion capabilities to its intended sandboxed workspace.

Why It Matters

The incident highlights ongoing concerns about AI agents and coding assistants operating with elevated system permissions. As these tools become integrated into developer workflows, ensuring proper containment boundaries between AI actions and critical user data becomes paramount. For enterprise users and individual developers alike, the ability to trust that an AI tool will respect file system boundaries is essential for adoption in production environments.

The Bottom Line

OpenAI has resolved the vulnerability in Codex. Users are encouraged to ensure their installations are updated to receive the latest security fixes.