๐Ÿ” CVE Alert

CVE-2026-19593

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.

CWE CWE-15
Vendor openai
Product codex desktop
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for openai codex desktop

Be the first to know when new unknown vulnerabilities affecting openai codex desktop are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OpenAI / Codex Desktop
260202.0859 โ‰ค 26.513.31313
OpenAI / Codex Desktop
26.304.38 โ‰ค 26.513.40821
OpenAI / Codex Desktop (Microsoft Store package)
26.304.38.0 โ‰ค 26.513.4821.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
openai.com: https://openai.com/codex

Credits

Satoki Tsuji (@satoki00) / Ikotas Labs, Inc.