Command Execution Flaw in OpenAI Codex for Windows, macOS, and Linux
CVE-2026-19591
What is CVE-2026-19591?
A vulnerability in OpenAI Codex CLI and Desktop allows an attacker to exploit misclassified PowerShell commands. Specifically, the command-safety parser interprets PowerShell’s stop-parsing token (--%) inaccurately, leading to potential execution of unauthorized commands. When a user accesses an attacker-prepared repository, Codex may execute malicious file-writing Git commands without requiring user consent. On macOS and Linux systems, exploitation is contingent upon having PowerShell Core installed. If filesystem permissions allow, this may alter Codex's configuration and could enable the launch of an attacker-mitigated MCP server. This operation could execute commands within the context of the user's privileges, posing risks of unauthorized file read, alteration, or deletion. Notably, while the approval bypass exists, inherent filesystem sandboxing may limit the extent of unauthorized writes.
Affected Version(s)
Codex CLI Windows 0.72.0 <= 0.130.0
Codex Desktop (Microsoft Store package) Windows 26.304.38.0 <= 26.513.4821.0
Codex Desktop macOS 260202.0859 <= 26.513.31313
