Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-19593: OpenAI Codex Desktop may run attacker code from Git repo
CVE-2026-19593 · published 2 days ago
Summary
When a user opens a workspace, Codex Desktop reads the Git settings of any repository in that workspace. If those settings have been maliciously modified, the program can launch the attacker’s code with the user’s own permissions, allowing the attacker to view, change, or delete files and steal credentials. To stay safe, avoid opening workspaces that contain repositories from untrusted sources, and make sure Git is not automatically reading custom configuration files from those repositories.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openai | codex desktop |
<= 26.513.31313 <= 26.513.40821 |
| openai | codex desktop (microsoft store package) | <= 26.513.4821.0 |
Original advisory text
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacke...
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.
References
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-15External Control of System or Configuration Setting
Timeline
Published1 Sep 2026
Updated3 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta