#repository-supply-chain

[ follow ]
Information security
fromTechzine Global
2 days ago

OpenAI Codex CLI contained dangerous MCP security gap

Codex CLI auto-executed MCP configurations from project folders, allowing cloned repositories with malicious .codex/config.toml and .env to run code on developers' devices.
[ Load more ]