Code Execution Vulnerability in OpenAI Codex for Multiple Platforms
CVE-2026-19592
What is CVE-2026-19592?
A vulnerability has been identified in OpenAI Codex products that involves the unintentional collection of Git repository metadata. This occurs when a user interacts with an attacker-controlled Git repository where the .git/config file has been altered to set core.fsmonitor to an external filesystem-monitor helper managed by the attacker. As a result, when Codex collects repository metadata, it could trigger the execution of the attacker's code outside of the application sandbox, allowing unauthorized access to the user's system. This may lead to the ability to manipulate, view, or delete files and access sensitive resources within the user's account.
Affected Version(s)
Codex CLI Windows 0.102.0 <= 0.130.0
Codex Desktop (Microsoft Store package) Windows 26.304.38.0 <= 26.513.4821.0
Codex Desktop macOS 260202.0859 <= 26.513.31313
