Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
Telerik UI for ASP.NET AJAX flaw chain allows unauthenticated remote code execution by exploiting a padding oracle and loading a malicious DLL.