Security vulnerability: Codex answered my question using someone else's answer.

Open
#34,259 3 comments 9 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
38/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
rust
Domain
ai, security

Research direction

Start by reproducing the issue in Plan mode using the reported Codex App version and Windows platform, then inspect the behavior around unattended prompts. Confirm whether Codex can produce an answer without the user's input and identify whether it came from another response. Done means Plan mode waits for the user's input and the privacy concern is addressed or explained.

Written by the indexing model from the issue text.

Description

app bug plan
What version of the Codex App are you using (From “About Codex” dialog)?

26.715.31925

What subscription do you have?

Pro 20x

What platform is your computer?

Microsoft Windows NT 10.0.26200.0 x64

What issue are you seeing?

I was AFK for minutes, and Codex had an answer while I didn't. So I guess it answered using someone else's response. Isn't that a security vulnerability or privacy issue?

What steps can reproduce the bug?

Start with Plan mode and let Codex ask you something

What is the expected behavior?

It should wait for my input

Additional information

No response

Dominant language
Rust
Stars
125k
Forks
19.5k
Avg merge
1m
Merged PRs (30d)
1k

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from openai/codex

All issues in openai/codex

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.