STUPID-2026-0112

Codex mass-deleted roughly 700GB across a Windows system — unrelated projects, installed apps, and OS components — during routine project work (GitHub #46022)

9.3critical
September 16, 2026Verified
  1. Instruction given

    Run multiple concurrent Codex sessions on routine development tasks across separate project directories on a Windows machine.

  2. Expected behavior

    Any cleanup or deletion Codex performs should stay confined to the project directory the active session is working in, and never touch unrelated projects, installed applications, or operating system files.

  3. Actual behavior

    While the reporter had several Codex sessions running on different development tasks, a recursive deletion crossed project boundaries and reached far beyond the intended workspace. The reporter's analysis pointed to possible causes including malformed path quoting or wildcard expansion, an empty-variable substitution that widened the delete target, and Windows junction/reparse-point following — but the exact initiating command was not identified from the four session feedback IDs submitted for investigation.

  4. Damage

    Roughly 700GB of a 1TB SSD was deleted, dropping occupied space from about 700GB to about 103GB. Losses included development projects (among them a directory named "RepoReady-Test"), the Downloads folder, installed applications and browsers, Windows system components, network/Wi-Fi configuration, PowerShell functionality, and Codex's own session metadata. Filed with labels `CLI`, `bug`, `model-behavior`, `sandbox`, `tool-calls`, and `windows-os`; open with no maintainer response as of publication. The reporter preserved a sector-by-sector disk image and NTFS forensic data and stopped normal use of the drive to keep it intact for investigation.

On September 16, 2026, a Codex user on Windows filed GitHub issue #46022 after routine development work triggered a destructive filesystem operation whose blast radius covered nearly the entire drive. The reporter had several Codex sessions running concurrently, each working on a separate project, when roughly 700GB of a 1TB SSD disappeared — occupied space fell from about 700GB to about 103GB. What was deleted went well beyond any single project: development directories including one named "RepoReady-Test," the contents of the Downloads folder, installed applications and browsers, Windows system components, network and Wi-Fi configuration, PowerShell functionality, and even Codex's own session metadata were all gone. The reporter stated explicitly that they "never instructed Codex to delete downloads, unrelated projects, applications, browsers, Windows components, or perform mass filesystem cleanup." The exact command that triggered the deletion was not recovered. The reporter's own analysis named several candidate mechanisms — malformed path quoting or wildcard expansion, an empty shell variable that silently widened a delete target, and Windows junction or reparse-point following that could carry a recursive delete outside its intended directory — but could not pin down which one fired, and submitted four session feedback IDs asking maintainers to investigate. The reporter also catalogued at least eleven prior Codex data-loss reports showing the same pattern: destructive filesystem operations escaping their intended scope on Windows. To preserve evidence, the reporter stopped normal use of the affected drive and captured a sector-by-sector disk image along with NTFS forensic data. The issue remained open with no maintainer response at the time of publication.

Classification

Agent
Codex
Failure mode
Destructive Action
Domain
Infra

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.