openai / openai/codex

Unauthorised file scans

Open
#42,434 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug CLI sandbox tool-calls windows-os
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of Codex CLI is running?

0.151

What subscription do you have?

Unauthorizated creating windows full profiles and reading secretly private information

Which model were you using?

GPT 5.2-codex

What platform is your computer?

Windows 10 X64

What terminal emulator and version are you using (if applicable)?

Powershell,CMD,python, Vs, NodeJs,

Codex doctor report
already delted it
What issue are you seeing?

I was running it it in cli when suddenly the AI told me exactly waht kind of BIOS i had, what version how old, from what year my laptop was and more information. After that he scanned all my chrome private files, i found ales toe the two accounts, i asked him to give me the passowrds, he said he couldnt but after a quick look ik can easily decompress them, so also lying to protect itself. I gave him NO acces to the whole computer but contained to 1 folder but still he totally ignored it. The Ai even sais that he didnt do nothing wrong becuase tis public information.............

Also using default profile and hiding it is not ethical and you should inform users better how your aii models are performing. i added my last conversation with the lm agent. you can find if

codex_log_chat.txt

What steps can reproduce the bug?

See othe reports sabout this

What is the expected behavior?

The AI shouldnt run under te hood commands there is nogpermission gave for, also not telling the truth about it want asking makes it forse. I takes me alot of time to delete all teh shit like the cua driver, the acconts your made, profiles everything.

Additional information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the attached codex_log_chat.txt and the report details for Codex CLI 0.151 on Windows 10. Attempt to reproduce the alleged file scans with access limited to one folder, then document whether commands or private files were accessed without permission and what evidence confirms the result.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli, operating-systems, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.