PT-2026-84357 · Openai · Openai Codex Desktop

CVE-2026-19593

·

Published

2026-09-01

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenAI Codex Desktop for Windows and macOS (affected versions not specified)
Description The application automatically inspects Git metadata and working-tree status upon opening a workspace. If a workspace contains a repository with a malicious .git/config file, the attr.tree setting and a configured clean or process filter can trigger Git to execute an attacker-controlled program. This execution occurs outside the command sandbox with the privileges of the signed-in user, bypassing workspace-trust prompts, command approvals, and model interactions. This allows an attacker to read, modify, or delete files and access user credentials. Successful exploitation requires Git to be available on the system PATH and the user to open a repository where the local Git configuration remains intact, as a standard Git clone does not copy the .git/config file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19593
ZDI-26-651

Affected Products

Openai Codex Desktop