codex will actually help you look but it will refuse to actually try and exploit it.
it won't for example create a POC python script that you normally would use to prove the issue.