Vulnerabilities/

Paperclip: codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email

Severity:
High

Description

A Paperclip-managed codex_local runtime was able to access and use a Gmail connector that I had connected in the ChatGPT/OpenAI apps UI, even though I had not explicitly connected Gmail inside Paperclip or separately inside Codex.

In my environment this enabled mailbox access and a real outbound email to be sent from my Gmail account.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
paperclipai
Anything's wrong? Let us know Last updated on April 16, 2026