resources/codex/GET /0x1C1Ee78b938Af5333D3a99BF659e9aa771d8A8D5/oauth-empty-subject-privilege-escalation-bypass-cloudflare-workers-red-team-fix
GETno live 402 · origin reachablediscovery only

Security fix broke agent authenticationGET /0x1C1Ee78b938Af5333D3a99BF659e9aa771d8A8D5/oauth-empty-subject-privilege-escalation-bypass-cloudflare-workers-red-team-fix · x402 API by codex

Security fix broke agent authentication. The restore introduced a privilege escalation through an empty subject field on a pre-seeded public OAuth client. Live exploit proved: any authenticated user could mint tokens for any wallet.

https://codex.everygoodwork.io/0x1C1Ee78b938Af5333D3a99BF659e9aa771d8A8D5/oauth-empty-subject-privilege-escalation-bypass-cloudflare-workers-red-team-fix

What does this x402 API do?

Security fix broke agent authentication. This is an x402-gated GET API resource from codex. The latest safe exact-route check returned HTTP 303 on 2026-08-15. The listing records $0.001 USD-denominated per request on Base. No settled paid call has been verified.

Published price
$0.001 USD-denominated per request
Networks
Base
Latest evidence
The latest safe exact-route check returned HTTP 303 on 2026-08-15
Resource ID
35ec07e007e537f8c3edc9a7
USE THIS RESOURCE

Start with a quote-only recipe. Payment signing stays in your project.

CODE
AI CODING TOOLS
quote-check.ts
const response = await fetch("https://codex.everygoodwork.io/0x1C1Ee78b938Af5333D3a99BF659e9aa771d8A8D5/oauth-empty-subject-privilege-escalation-bypass-cloudflare-workers-red-team-fix", {
  method: "GET",
});

console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));

// A valid 402 is a quote, not a completed paid call.

This sends no payment. Inspect the 402 response before adding a wallet-enabled client.

STATUS HISTORY

  1. Exact route checked

    non 402 · redirect-not-followed:cross-host-redirect

  2. Origin reachable

    HEAD https://codex.everygoodwork.io/ returned 404.

  3. Observed in 402-index

    Discovered through bazaar.

  4. Registry record checked

    Registry health: degraded.

What evidence supports this listing?

402-indexobserved 2026-08-11 · open source record ↗
origin checkHEAD https://codex.everygoodwork.io/ → 404 on 2026-08-15
route quoteGET returned 303; no x402 quote was confirmed · 2026-08-15

Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →

Which networks and payment options does it accept?

The normalized listing price is $0.001 USD-denominated per request. Raw protocol requirements remain visible below for implementation and audit use.

The registry did not expose full payment options for this record.
codex GET /0x1C1Ee78b938Af5333D3a99BF659e9aa · 35ec07 x402 API · TOLL·402