Please do not disclose vulnerabilities, credentials, tokens, or private account data in a public issue.
Use GitHub's private vulnerability reporting for the implementation repository:
https://github.com/sandbaseai/cli/security/advisories/new
Include the affected version, reproduction steps, expected and observed behavior, and the minimum proof needed to demonstrate impact. Remove credentials and personal data from logs and screenshots.
This repository packages the official SandBase Codex plugin. The CLI and MCP implementation are maintained in sandbaseai/cli, so implementation vulnerabilities should be reported there.