Digest / February 20, 2026
Codex Issues Digest — February 20, 2026
42 new issues filed ·
67 resolved in openai/codex (UTC day).
New issues (42)
- Rules: Extend it to configure sandbox_policy
- Config: Add support for --add-dir in config.toml
- Snowflake MCP streamable_http fails at initialize with "error decoding response body" while same PAT/server works in Cursor
- Agent executes backticks in git commit message (command substitution)
- `--model` flag accepted but fails with "model not supported" on ChatGPT accounts
- "You've hit your usage limit." Despite 10% Rate Limit Usage Remaining
- Final Korean character is inserted into next pending input after option 3 in command approval modal
- The area that displays GPT’s changes is too small to see details
- Agent terminal hangs on pnpm install and pnpm build while commands run normally in local shell (Linux)
- Display active Project/Session name in Desktop App window title
- Failed to start code review
- Codex CLI error.
- macOS app: Voice message is posted to the wrong thread if user switches threads while transcription is processing
- Desktop: stale 'Running N terminals' shown after all processes are already dead
- bwrap block file modifications in the workspace direcotry
- Large JSON pastes crashes your Mac kernel
- Thread name in /statusline
- Expose turn/steer in the TypeScript SDK
- Flaky codex-core unified_exec test: race in reusing_completed_process_returns_unknown_process
- SKILL-mode output sometimes leaks wrapper-like text and stray Unicode fragments
- Codex CLI multi-agent spawns duplicate Serena MCP instances instead of sharing one connection
- Add automatic lifecycle cleanup for completed/idle sub-agents (and unused MCP clients)
- Add `--max-turns` CLI option
- Workaround for Rust 1.90.0 relevant to OpenBSD 7.8
- Add support for installation on OpenBSD
- TUI: Option/Ctrl+Arrow word navigation is not CJK/Unicode-aware
- Better notification for multi-agent
- Security concern: CodexSandboxOffline/Online assigned to entire user profile tree on Windows 11
- Worktree setup fails when repo has no main branch (fatal: invalid reference: main). Should prompt for base branch.
- apply_patch fails with Access is denied on mapped/UNC Windows worktrees
- Pressing "n" should not cancel a tool call
- https://github.com/github/docs/issues/41645#issue-3687401622
- Agent unable to read new file in worktree mode.
- Manually added skills don't auto-suggest when typing '$' until the app is restarted.
- [](https://codespaces.new/openai/codex?quickstart=1)
- Make 'snapshot_shell' store non-exported environment
- Support for overriding Model metada
- CLI: resume can get stuck on Working after unclean disconnect/shutdown of an active turn
- [Enhancement] Pin TODO List to the bottom
- Allow Codex to load images into context by itself
- Creating a skill + automation does not trigger immediate execution
- Allow multiple CLI terminals per project
Resolved issues (67)
- Worktree functionality missing
- Shell snapshot validation fails on macOS Bash (unexpected token '(') – v0.103.0
- Expose turn/steer in the TypeScript SDK
- Codex CLI error.
- macOS app: Voice message is posted to the wrong thread if user switches threads while transcription is processing
- Flaky codex-core unified_exec test: race in reusing_completed_process_returns_unknown_process
- SKILL-mode output sometimes leaks wrapper-like text and stray Unicode fragments
- Codex CLI multi-agent spawns duplicate Serena MCP instances instead of sharing one connection
- Workaround for Rust 1.90.0 relevant to OpenBSD 7.8
- Codex app crashes silently during task execution on MacBook Pro (M2 Pro)
- VS Code Codex: CPU usage to 100% when using 0.4.71 version
- Codex 5.3 Disconnecting and Running Extremely Slowly
- Can't open app in Tahoe 26.2 (25C56)
- execution error: Io(Error { kind: InvalidInput, message: "batch file arguments are invalid" })
- Plan Mode bugs
- Codex cli keep resets to gpt-5.2-codex meduim
- Codex app-server stuck at 100% CPU on macOS Apple Silicon when opening VS Code ChatGPT extension
- Pressing "n" should not cancel a tool call
- https://github.com/github/docs/issues/41645#issue-3687401622
- Add support for WebStorm in "Open In" list
- Agent unable to read new file in worktree mode.
- [](https://codespaces.new/openai/codex?quickstart=1)
- Your prompt was flagged as potentially violating our usage policy. Please try again with a different prompt
- False positive cyber-risk rerouting (routed to GPT-5.2)
- Cybersecurity Block for Benign Use
- False-positive “high-risk cyber activity” flag blocks gpt-5.3-codex in Codex CLI
- Getting routed to 5.2 after ID check.
- False Positive - Flagged For Cyber Security Risk
- Account was flagged incorrectly
- Your account was flagged for potentially high-risk cyber activity
- [CODEX CLI] Rerouted to 5.2 from 5.3 even after succesfull cyber verification on PRO PLAN
- IìMy account has been mistakenly flagged as high-risk cyber activity
- A false positive cyber-safety flag.
- Request Re-Routed for Cyber Risk False Positive
- False positive: Codex cyber-safety flag during normal UI/dev work
- cybersecurity flagging for benign gpt-5.3-codex usage
- GPT-5.3 requests automatically routed to GPT-5.2 under “Trusted Access for Cyber” (Pro subscription)
- False positive: account flagged for cyber activity and routed to gpt-5.2 fallback
- False positive cyber-safety routing. gpt-5.3-codex usage
- False positive cyber-risk rerouting (re-routed to GPT-5.2)
- False positive cyber-risk
- False positive: routed to GPT-5.2 due to “cyber-abuse risk” during normal dev work
- High Risk Cyber Activity Bug
- False positive: account flagged for cyber activity and routed to gpt-5.2
- Your account was flagged for potentially high-risk cyber activity and this request was routed to gpt-5.2 as a fallback
- Your request was routed to GPT-5.2. - Cannot use GPT 5.3 Codex anymore
- Thread ID 019c7161-0657-7bd1-b940-f315d6b2e03b inappropriately flags high-risk cyber activity for mundane style work
- SOLUTION - HIGH RISK CYBER SECURITY -> LOG OUT / LOG IN AFTER VERIFYING PERSONA
- Flagged for high-risk cyber activity when updating Codex config
- False‑Positive “High‑Risk Cyber Activity” Flag
- Locked out of using gpt-5.3-codex suddenly while doing nothing malicious, cyber website not working showing ineligible!
- 019c51ab-5625-7f03-994f-6aad706ceb7f False positive: Your request was re-routed to reduce cyber-abuse risk
- When using Codex, I encountered a problem where I needed to verify my identity via Trusted Access for Cyber. I uploaded my ID card, but I couldn't get through.
- False positive — account flagged for “potentially high-risk cyber activity” and rerouted to GPT-5.2
- account flagged for “potentially high-risk cyber activity” and rerouted to GPT-5.2
- flagged for high risk cyber
- Bug: incorrectly flagged for cyber while building app; routed to GPT-5.2 Codex
- Your account was flagged for potentially high-risk cyber activity and this request was routed to gpt-5.2 as a fallback.
- False Positive: High Risk Cyber Activity
- Randomly flagged for cyber security coding when doing research on HW products
- False Positive: Cyber
- Flagged accounts - larger concerns
- Config: Add support for --add-dir in config.toml
- stream disconnected before completion
- stream disconnected before completion
- [Enhancement] Pin TODO List to the bottom
- Allow Codex to load images into context by itself