4.1
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.
Basic Information
ID
CVE-2025-54558
Source
mitre
Published
Jul 25, 2025 at 00:00
Modified
Jul 25, 2025 at 13:23
Affected Product
Vendor
OpenAI
Product
Codex CLI
Affected Versions
OpenAI Codex CLI 0