Only the latest published Codex Remote Runtime Beta receives security fixes. Pre-release versions do not carry a production support or compatibility commitment.
Use the affected repository's Security > Report a vulnerability form. If
you cannot determine the owning repository, email lihuo0229@outlook.com.
Do not open a public issue for an unresolved vulnerability.
Include the affected version or commit, reproduction steps, observed impact, and the smallest evidence needed to understand the problem. Remove project content, prompts, credentials, pairing links, QR codes, personal paths, and unrelated diagnostics.
Do not test against systems, devices, networks, or accounts you do not own or have explicit permission to assess.
- The current Beta is unsigned and not Apple notarized.
- Phone access is intended for a trusted local network; direct public-internet exposure is unsupported.
- Pairing links and QR codes contain one-time credentials and must remain private.
- Source access is limited to configured workspace roots and must not be used to disclose unrelated local files.