CVE-2026-14898: Codex macOS app image rendering enables prompt-injection data exfiltration
The OpenAI Codex desktop app for macOS automatically fetched remote images referenced in Markdown model responses, allowing an indirect prompt injection to encode session secrets into an image URL that was sent to an attacker-controlled server without user interaction. Exploitation could leak API keys, source code and data returned by connected tools.
Disclosed 6 July 2026 · Record updated 13 September 2026
Impact
Potential exfiltration of secrets accessible in the Codex session, including API keys, source code and connected-tool data; no integrity or availability impact demonstrated and no known exploitation in the wild.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-14898
