product updateOpenAI

OpenAI Patches Codex Bug That Let AI Agent Delete Real User Files

TL;DR

OpenAI has shipped a security update for Codex after users reported that GPT-5.6 Sol was autonomously deleting real files instead of temporary ones. The bug stemmed from misused system variables like $HOME pointing cleanup commands at actual home directories.

2 min read
0

OpenAI has fixed a Codex bug that caused the coding agent to delete real user files without permission, according to the company. The issue affected GPT-5.6 Sol, the model powering Codex, which was found autonomously wiping data during normal operation.

What went wrong

According to OpenAI, the root cause was a command intended to clean up temporary working files. Instead of targeting scratch directories, the command sometimes pointed at actual user data. The failure occurred when the model used system environment variables — specifically $HOME — to construct paths for temporary folders. A faulty delete command built on top of that variable ended up resolving to the real home directory rather than an isolated temp location, and Codex proceeded to delete files it had no business touching.

Multiple users reported the behavior before OpenAI issued a fix, according to the source report.

The fix

OpenAI's security update introduces several changes to Codex's file-handling behavior:

  • Codex now verifies deletion targets before executing delete commands
  • The agent creates fresh, isolated temporary folders instead of reusing system paths
  • Codex no longer misuses system environment variables like $HOME for temp storage
  • Stricter checks flag and block risky delete commands before execution
  • Full-access mode — which grants Codex broader filesystem permissions — can no longer be triggered accidentally

OpenAI is recommending that users run Codex in one of its sandboxed modes rather than full-access mode, and to keep the application updated to receive the patch.

What this means

This bug is a reminder that autonomous coding agents operate with real filesystem permissions, and a single mishandled environment variable can turn a routine cleanup operation into irreversible data loss. Unlike a chatbot hallucination that produces bad text, an agent with file-system access that misfires produces bad actions — deleted files, corrupted directories, no easy undo.

The specific failure mode here — trusting $HOME or similar variables without validating the resolved path — is a known class of bug in shell scripting and automation tools generally, not something unique to AI agents. What's new is that an LLM is now the one writing and executing these commands autonomously, often across many files and sessions without a human reviewing each step. That raises the stakes: a bug that might have caused one bad rm -rf in a hand-written script can, in an agentic loop, repeat across an entire session before anyone notices.

OpenAI's fix — verify-before-delete, isolated temp directories, and blocking accidental full-access mode — is a sensible baseline, but it also underscores that coding agents need the same defensive engineering rigor as any system with destructive filesystem access: sandboxing by default, explicit confirmation for irreversible operations, and no implicit trust in environment state. Expect other agent vendors — GitHub Copilot Workspace, Cursor/Anysphere, Replit, and similar tools — to face scrutiny over whether their own delete and file-write pathways have equivalent safeguards.

Related Articles

product update

GPT-6 Astra Ultrafast Claims Up to 8x Faster Token Generation on NVIDIA Blackwell GPUs

GPT-6 Astra Ultrafast, running on NVIDIA Blackwell GPUs, is available now in the OpenAI API and to eligible ChatGPT Work and Codex users. NVIDIA says it generates tokens up to 8x faster than Astra Standard mode. Pricing and context window details were not disclosed in the source.

product update

OpenAI publishes startup guide for GPT-6 family covering model choice, reasoning effort and tool coordination

OpenAI has published "A model guide for the GPT-6 family," a practical guide aimed at startups. It covers choosing GPT-6 models, tuning reasoning effort, improving prompts and skills, coordinating tools, and preparing workflows for production. The summary gives no pricing, context window or benchmark figures.

analysis

OpenAI publishes startup guide to choosing and deploying GPT-6 models, with reasoning-effort tuning

OpenAI has published a practical guide for startups building on the GPT-6 family. It covers model selection, reasoning effort, prompts and skills, tool coordination, and production workflows. The available summary discloses no pricing, context window, or benchmark figures.

analysis

Ramp AI Index: US business AI spending falls while usage rises about 50% from July peak

US companies are spending less on AI even as usage hit a record high at the end of September, according to the latest Ramp AI Index. Ramp economist Ara Kharazian attributes the drop almost entirely to price competition between OpenAI and Anthropic. In the last week of September, Anthropic took 51% of token spending and OpenAI 44.5%.

Comments

Loading...