OpenAI's Codex CLI has always been pitched as a productivity booster for developers—an AI-powered assistant that can read, edit, and run code straight from the terminal. But a recent discovery shows that convenience can come with a hidden price. Security researchers have uncovered a critical vulnerability that turns everyday developer workflows into potential attack vectors, and the implications stretch far beyond a simple bug.

