Open AI2 mins read

OpenAI open-sources Codex Security CLI for finding and fixing code vulnerabilities

OpenAI has released Codex Security CLI, an open-source command-line tool designed to help developers and security teams detect, confirm, and fix vulnerabilities in code repositories.

OpenAI red logo image for Codex Security CLI coverage
Image credits:The Decoder

What OpenAI released

OpenAI has released Codex Security CLI, an open-source command-line tool for security and development teams. The tool is licensed under Apache 2.0 and is designed to help find, confirm, and fix vulnerabilities in code repositories.

Codex Security CLI is currently in beta and installs via npm. Teams evaluating it should account for its runtime requirements: Node.js 22 and Python 3.10 or higher.

How it fits into developer workflows

Codex Security CLI can scan repositories, compare results across multiple runs, verify fixes, and connect security checks to CI/CD pipelines. It also supports bulk scans across multiple repositories, making it relevant for teams managing more than one codebase.

The practical takeaway: this is positioned as a developer-facing security tool, not just a standalone scanner. Its command-line format makes it easier to bring vulnerability checks closer to everyday engineering workflows.

Why the release matters

Codex Security was previously known internally as “Aardvark” and launched in March 2026 as a research preview for ChatGPT Enterprise, Business, and Edu customers. According to OpenAI, the system had helped fix more than 3,000 critical vulnerabilities by April 2026.

The tool also enters a competitive space: The Decoder reports that it competes directly with Anthropic’s Claude Security, which also scans codebases for vulnerabilities and suggests patches. The broader implication is clear: as AI increases automation on the attack side, defensive tools are becoming more automated too.

What teams should check before adopting it

Before adding Codex Security CLI to production workflows, teams should review its beta status, supported commands, output formats, and CI/CD integration options. They should also confirm that their environments meet the Node.js and Python requirements.

The strongest near-term use case is likely structured security review inside existing repository and pipeline processes. For teams already testing AI-assisted development tools, Codex Security CLI offers a focused way to evaluate AI-assisted vulnerability detection and remediation from the command line.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile