OpenAI Codex Desktop Vulnerability in Windows and macOS
CVE-2026-19590

Currently unrated

Key Information:

Vendor

Openai

Vendor
CVE Published:
1 September 2026

What is CVE-2026-19590?

A vulnerability in OpenAI Codex Desktop for Windows and macOS allows malicious actors to execute unauthorized Git hooks through a flawed configuration of the repository's core.hooksPath setting. When users open a compromised repository where the .git/config file directs to an attacker-controlled directory, Codex can inadvertently execute harmful commands outside of its secure command sandbox. This occurs without user consent and runs with the user's privileges, leading to potential unauthorized access or modification of user files and resources in the account. Standard Git clone operations do not retain the exploitative local configurations required for this vulnerability to be activated.

Affected Version(s)

Codex Desktop (Microsoft Store package) Windows 26.304.38.0 <= 26.513.4821.0

Codex Desktop macOS 260202.0859 <= 26.513.31313

Codex Desktop Windows 26.304.38 <= 26.513.40821

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam).
.