Codex AI Game Studio

Security policy

Supported versions

Security fixes are provided for the latest released major version. During the v1 preview, 1.x is supported.

Report a vulnerability

Please use GitHub's **Report a vulnerability** private security-advisory form for this repository. Do not post exploitable details in a public issue or Discussion. Include:

You should receive an acknowledgement within seven days. Coordinated disclosure timing will be agreed after triage. There is no paid bug-bounty program.

Security boundaries

Out of scope

Vulnerabilities in an external engine, DCC application, model, repository, package registry, or MCP server should be reported to that upstream project. If the catalog metadata or adapter exposes users to it, also report the integration impact here.