T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/gpt-web-login-bridge.js:86- Finding
Prompt-Controlled Codex Agent Can Read and Disclose Local Workspace Files
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gpt-web-login-bridge.js, lines 86-103
Vulnerability Type: Excessive local file access during provider-backed prompt execution
Risk Level: HighVulnerable Code
js function codexAsk(prompt) { const result = runCodex([ 'exec', '--ignore-user-config', '--ignore-rules', '--skip-git-repo-check', '--ephemeral', '--json', '-C', bridgeCwd, '-s', 'read-only', '-c', 'approval_policy="never"', '-c', 'model_reasoning_effort="low"', prompt, ]);Technical Analysis
The bridge passes arbitrary caller-controlled prompt text to a Codex agent operating in
bridgeCwd. Theread-onlysandbox prevents filesystem modification, but it does not prevent the agent from reading files available within its execution context.The use of
--ignore-rulesalso disables repository-level rules that might otherwise limit file inspection or regulate handling of sensitive project data. Meanwhile,approval_policy="never"means tool operations proceed without an interactive approval boundary where permitted by the sandbox.Consequently, the effective provider data boundary is broader than the submitted prompt. Local source code, configuration files, credentials stored in readable project files, and other workspace content may enter the provider context through agent tool calls.
Attack Path
- A user, another skill, or an untrusted automation component invokes the bridge using the
askcommand. - The supplied prompt instructs the Codex agent to inspect files, such as configuration files, deployment manifests, source files, or hidden files in the working directory.
- The bridge starts Codex in
bridgeCwdwith read-only filesystem access and repository rules disabled. - Codex uses its available tools to read accessible local files.
- File contents are submitted to the authentica ...[truncated 681 chars]
- A user, another skill, or an untrusted automation component invokes the bridge using the
- Remediation
View remediation
Remediation Suggestions
- Use a provider mode that does not expose filesystem or shell tools when the intended operation is only a text model request.
- Run Codex from a newly created, empty, permission-restricted working directory rather than from the caller-selected project directory.
- Do not use
--ignore-rulesunless repository rules have been independently validated and intentionally replaced with stricter bridge-specific controls. - Enforce an allowlist of readable files if local context is required, and copy only approved content into an isolated directory.
- Separate plain prompt completion from agentic repository operations. Require an explicit, separately authorized command for any operation that grants local file access.
- Clearly disclose that local file contents and tool results—not only the original prompt—may be sent to the authenticated provider.
- Reject or require additional confirmation for prompts requesting file inspection, secret discovery, environment inspection, or recursive workspace analysis.
