CVE-2025-61260 — OpenAI Codex CLI Command Injection via Project-Local Configuration
During testing, we found that Codex CLI will automatically load and execute MCP server entries from a project-local configuration whenever codex is run inside that repository. Concretely, if a repo...