CVE-2026-19590
Summary
| CVE | CVE-2026-19590 |
|---|---|
| State | PUBLISHED |
| Assigner | OAI |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-01 18:17:40 UTC |
| Updated | 2026-09-03 15:17:19 UTC |
| Description | OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation. |
Risk And Classification
Primary CVSS: v3.1 7.3 HIGH from ADP
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.001030000 probability, percentile 0.010630000 (date 2026-09-07)
Problem Types: CWE-427 | CWE-427 CWE-427: Uncontrolled Search Path Element
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | OpenAI | Codex Desktop | affected 260202.0859 26.513.31313 custom | macOS |
| CNA | OpenAI | Codex Desktop | unaffected 26.519.22136 | macOS |
| CNA | OpenAI | Codex Desktop | affected 26.304.38 26.513.40821 custom | Windows |
| CNA | OpenAI | Codex Desktop | unaffected 26.519.21041 | Windows |
| CNA | OpenAI | Codex Desktop Microsoft Store Package | affected 26.304.38.0 26.513.4821.0 custom | Windows |
| CNA | OpenAI | Codex Desktop Microsoft Store Package | unaffected 26.519.2081.0 | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/openai/codex/pull/22843 | 8f4f43ab-ba69-4d92-aa1d-d772184d6fb7 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam). (en)
Additional Advisory Data
Solutions
CNA: Upgrade Codex Desktop for macOS to application version 26.519.22136 or later, or Codex Desktop for Windows to application version 26.519.21041 (Microsoft Store package 26.519.2081.0) or later.
Workarounds
CNA: Until updated, do not open untrusted repository archives or copied repository directories that preserve attacker-supplied .git/config.
There are currently no legacy QID mappings associated with this CVE.