T05 · Unauthorized Access and Privilege Escalation
- Location
references/troubleshooting.md:119- Finding
Unsafe Recommendation to Disable Codex Sandbox Isolation
- Content
View full analysis
Vulnerability Details
File Location:
references/troubleshooting.md:119-127
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: HighVulnerable Code Snippet:
toml [sandbox_workspace_write] network_access = trueOr run with full network access:
bash codex exec --sandbox danger-full-access "nlm notebook list"Technical Analysis
The troubleshooting guide recommends
--sandbox danger-full-accesswhen network access is unavailable. This mode removes sandbox restrictions instead of granting only the network capability required by the NotebookLM operation.The command executed inside the unrestricted environment is resolved from the user's local executable search path. If the
nlmexecutable or one of its dependencies has been replaced, compromised, or shadowed by an attacker-controlled executable, it can operate with the invoking user's full host permissions. The sandbox bypass therefore expands a network troubleshooting action into unrestricted filesystem, process, credential, and network access.The preceding
network_access = trueconfiguration is the narrower option, while the unrestricted fallback violates least-privilege principles.Attack Path
- An attacker compromises the installed
nlmpackage, one of its runtime dependencies, or places a malicious executable namednlmearlier in the user'sPATH. - The user encounters the documented sandbox network error.
- Following the troubleshooting guide, the user executes:
codex exec --sandbox danger-full-access "nlm notebook list". - Codex launches the attacker-controlled or compromised executable without normal sandbox isolation.
- The executable reads or modifies files accessible to the user, accesses local credentials and browser data, communicates with external systems, or launches additional processes.
Impact Assessment
Exploitation can provide access equivalen ...[truncated 399 chars]
- An attacker compromises the installed
- Remediation
View remediation
Remediation Suggestions
- Remove the
--sandbox danger-full-accessrecommendation. - Retain sandbox isolation and enable only the required outbound network capability, such as the documented
network_access = truesetting. - Restrict outbound access to NotebookLM and required Google authentication endpoints where the execution environment supports destination allowlisting.
- Instruct users to verify the resolved executable before use, for example with
command -v nlm, and to install it only from a trusted, pinned source. - If unrestricted execution is unavoidable, clearly explain the affected security boundary and require explicit user approval after displaying the executable path and risks.
- Remove the
