On August 12, 2026, between approximately 21:48 and 21:55, a recursive deletion occurred on my Windows computer while I was using the Codex App. The deletion affected the root of the C: drive, Program Files, and other directories outside the project folde

Hello,

I am reporting a serious data-loss incident that occurred on August 12, 2026, while I was using the Codex App for Windows.

I am only including details that I can currently confirm from the available records.

The incident occurred between approximately 9:48 PM and 9:55 PM. During that period, a recursive deletion was executed in Windows. The deletion was not limited to the intended project folder. It affected the root of my C: drive, Program Files, and other directories.

The affected drive is a 1TB NVMe SSD using NTFS, with TRIM enabled.

After the incident, Windows could still start, but many Windows functions and installed applications no longer worked because a substantial number of files had been deleted.

I did not format the drive, run CHKDSK, reinstall Windows, or intentionally delete these system directories. After realizing what had happened, I focused on preserving the remaining data and investigating recovery options.

I have reviewed the available Codex task history. The visible task from that day mainly concerned diagnosing a CorelDRAW 2020 plugin problem. However, I have not yet located the exact command responsible for the large-scale deletion in the records available to me.

Therefore, I am not claiming that I have already determined the precise technical cause. I am asking OpenAI to investigate the relevant Codex session and command-execution logs.

In particular, I would like OpenAI to determine:

  • Which session or task initiated the deletion
  • The exact command that was executed
  • The working directory at the time
  • The path or variable that was passed to the deletion command
  • How the deletion target was resolved
  • Whether the command required or received user approval
  • Why files outside the intended project directory were affected
  • Whether the Windows app’s permission, sandboxing, or workspace restrictions functioned as intended

This incident caused serious damage to my Windows installation and resulted in the loss of a substantial amount of data. Because the affected disk is an NVMe SSD with TRIM enabled, recovery may be difficult or incomplete.

I believe this incident deserves urgent investigation. Even when broad permissions are enabled, a development agent should provide a clear warning and request explicit confirmation before executing a recursive deletion that can affect the root of a system drive, Program Files, user directories, or other locations outside the selected workspace.

I would also recommend that the Codex App for Windows implement stronger protections, including:

  • Strict validation of recursive deletion targets
  • Protection for drive roots and Windows system directories
  • Clear warnings showing the fully resolved target path
  • Explicit confirmation for deletion outside the selected workspace
  • Limits on unresolved, empty, or unexpectedly broad path variables
  • Reliable logging of commands, working directories, approvals, and resolved paths
  • An emergency stop mechanism for destructive filesystem operations

If an OpenAI team member sees this report, please let me know how I can provide the relevant session ID, timestamps, screenshots, recovery information, and any locally available logs through a private channel. I do not want to publish sensitive logs or personal filesystem paths publicly.

Thank you.