Project Subscriptions
No data.
No advisories yet.
Solution
Update Codex Desktop for macOS to application version 26.519.22136 or later, or Codex Desktop for Windows to application version 26.519.21041 (Microsoft Store package 26.519.2081.0) or later.
Workaround
Until updated, do not open attacker-supplied workspace folders that retain untrusted .git metadata.
| Link | Providers |
|---|---|
| https://openai.com/codex |
|
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself. | |
| Weaknesses | CWE-15 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OAI
Published:
Updated: 2026-09-01T17:10:24.909Z
Reserved: 2026-08-12T03:54:42.487Z
Link: CVE-2026-19593
No data.
Status : Awaiting Analysis
Published: 2026-09-01T18:17:40.480
Modified: 2026-09-01T21:03:04.987
Link: CVE-2026-19593
No data.
OpenCVE Enrichment
No data.