BleepingComputer (2026-09-20) covers Accomplish AI’s research on OpenAI Codex sandbox escapes: Heapjack ran unsandboxed host commands from Codex Desktop’s read-only mode (for example after opening someone else’s repo), and Overpatch abused the CLI apply_patch path to write outside the workspace. Reported Aug 12 and fixed in about eight days. Version floors: Desktop 26.818.21641; CLI 0.149.0.

Same week — disclosed Sep 17–18, so label the dates honestly — Air Security’s Plugin4Shell shows agents that pin a marketplace commit hash but don’t verify the working tree. Hosts that allow hash-shaped branches can serve different code. Affected: Claude Code, Codex, GitHub Copilot, Gemini CLI. Fixes cited: Claude Code 2.1.179; Codex 0.146.0; Copilot unfixed as of THN Sep 18; Gemini CLI won’t be patched (migrate). No known in-wild use per THN.

If staff run coding agents on laptops: enforce those version floors, treat untrusted repos as hostile, and don’t assume plugin auto-update is a supply-chain control — especially Copilot and non-GitHub plugin hosts.