Skip to content
IonWarpRouterTry for free
Codex Security

Add Security Review
to your Codex pull requests.

OpenAI's Codex Security scans a repository for vulnerabilities. IonWarp reviews pull requests for the security holes they add.

Pull request review preview

IonWarpbotexample review

IonWarp Review — PR #87

3 issues| 2 P0 1 P1
#SevIssueFile
1Request ID lets a member read another workspaceapi/projects/[id].ts
2Provider secret included in the public client bundleapp/config.ts
3Unsigned webhook can enqueue account actionsapi/webhooks.ts
api/projects/[id].ts
42434445
−+++
const project = await projects.get(params.id);const project = await projects.getForMember({  projectId: params.id, userId: session.user.id,});

A signed-in user can cross the workspace boundary · Security Review

The endpoint authenticates the caller but never binds the requested project to their membership. Changing the URL ID returns another workspace’s private project. Resolve membership before returning it.

Suggested fixAI fix prompt

What Codex Security does, and what a pull request security review adds

Codex Security is OpenAI's application security agent: it helps teams find, confirm and fix vulnerabilities, from the Codex app, a CLI and SDK, or Codex cloud for connected GitHub repositories.[1] It builds a threat model of the repository, ranks likely issues, then tries to reproduce each one in a clean container. It never applies a patch for you: you review it before creating a draft pull request.[2]

IonWarp's Security Review works on the pull request. The planner adds it when a change needs it, and its findings land on the pull request before merge. On 13 benchmark pull requests with 18 known security issues, DeepSeek v4.1 Flash, the model it runs, scored an F1 of 62.5% for about 6 cents a review, ahead of CodeRabbit (54.1%), Greptile (53.8%) and Cursor Bugbot (50.0%). The Qodo app scored 73.3%.[3]

Security holes IonWarp caught that review apps missed

  • A CSRF check that checked nothing

    In Sentry #67876 the GitHub OAuth state was the pipeline's fixed signature, the same for every user, so the CSRF check did nothing. DeepSeek v4.1 Flash flagged it; Bugbot, CodeRabbit and Greptile did not.[4]

    Security ReviewOn Starter, Pro and Max

  • An embed gate any client could pass

    In a Discourse pull request from the benchmark, the embed endpoint's only gate was a Referer header any client can set, and it sent X-Frame-Options: ALLOWALL. DeepSeek v4.1 Flash and GLM 5.3 Flash flagged it; all four review apps missed it.[5]

    Security ReviewOn Starter, Pro and Max

  • A login that could skip the password

    Cal.com #10600 added two-factor backup codes. Three models we benchmark for this reviewer flagged that the login could accept a code without the password; the answer key had no such issue, so it was graded false.[6] Cal.com later published a password bypass in that login code as CVE-2025-66489.[7]

    Security ReviewOn Starter, Pro and Max

IonWarp and Codex Security

OpenAI facts are from its Codex Security documentation, read on 2026-10-04; numbered notes link to each page.

IonWarp and Codex Security
CriterionIonWarpCodex Security
What it isA security reviewer in a GitHub app; the planner adds it to the pull requests that need itAn application security agent that helps teams find, confirm and fix vulnerabilities[1]
What it readsA pull request's changes and the code around themA repository or a folder, a pull request or branch before merge, or the new commits it monitors[1][2]
What it returnsFindings on the pull request with a severity, the attack path, a suggested fix and an AI fix promptRanked findings with criticality, validation evidence, remediation guidance and a proposed patch when one is available[2]
Changes to your codeNone: the GitHub app reads code and never pushesNo patch is applied for you; you review it before creating a draft pull request[2]
Where it runsIonWarp's hosted serviceThe Codex app, the open-source CLI and SDK, or Codex cloud for connected GitHub repositories[1][8]

Starter is free for 3 seats. Pro is $49 a month with 5 seats, and Max is $149 a month with 10 seats. Compare plans

FAQ

Frequently asked questions

Sources

  1. Codex Security — OpenAI, read 2026-10-04.
  2. Codex Security: Cloud FAQ — OpenAI, read 2026-10-04.
  3. The security review benchmark: 13 pull requests, 18 known issues (release of 2026-09-24) — IonWarp benchmark, read 2026-10-03.
  4. getsentry/sentry #67876 (OAuth state), graded security findings — IonWarp benchmark, read 2026-10-04.
  5. discourse #4 (embed URL handling), graded findings — IonWarp benchmark, read 2026-10-03.
  6. calcom/cal.com #10600 (2FA backup codes), graded security findings — IonWarp benchmark, read 2026-10-03.
  7. CVE-2025-66489: Authentication bypass via bad TOTP and password checks — Cal.com on GitHub, read 2026-10-03.
  8. openai/codex-security — OpenAI on GitHub, read 2026-10-04.

Get a review on your next pull request

Install IonWarp on GitHub. Starter is free for 3 people, with 15,000 credits to start.

Try for free