Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Codex Desktop for macOS to application version 26.519.22136 or later, or Codex Desktop for Windows to application version 26.519.21041 (Microsoft Store package 26.519.2081.0) or later.
Vendor Workaround
Until updated, do not open attacker-supplied workspace folders that retain untrusted .git metadata.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://openai.com/codex |
|
Wed, 02 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openai
Openai codex Desktop Openai codex Desktop (microsoft Store Package) |
|
| Vendors & Products |
Openai
Openai codex Desktop Openai codex Desktop (microsoft Store Package) |
Wed, 02 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Code Injection via Untrusted Git Repository in OpenAI Codex Desktop |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself. | |
| Weaknesses | CWE-15 | |
| References |
|
Status: PUBLISHED
Assigner: OAI
Published:
Updated: 2026-09-02T17:19:30.681Z
Reserved: 2026-08-12T03:54:42.487Z
Link: CVE-2026-19593
Updated: 2026-09-02T17:19:11.031Z
Status : Awaiting Analysis
Published: 2026-09-01T18:17:40.480
Modified: 2026-09-02T18:19:16.337
Link: CVE-2026-19593
No data.
OpenCVE Enrichment
Updated: 2026-09-02T21:39:17Z
-
CWE-15
External Control of System or Configuration Setting