Vulnerability in codex project
Resolved 💬 1 comment Opened Mar 26, 2026 by ankitdn Closed Mar 26, 2026
What is the type of issue?
_No response_
What is the issue?
While working on codex project, I scanned the dependency manifest and found that it uses a vulnerable version of yaml. The scan revealed a stack overflow issue where deeply nested YAML collections can trigger a “Maximum call stack size exceeded” error, potentially causing the application to crash when processing untrusted input.
Where did you find it?
_No response_
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗