Code Execution Vulnerability in OpenAI Codex for Multiple Platforms
CVE-2026-19592

Currently unrated

Key Information:

Vendor

Openai

Vendor
CVE Published:
1 September 2026

What is CVE-2026-19592?

A vulnerability has been identified in OpenAI Codex products that involves the unintentional collection of Git repository metadata. This occurs when a user interacts with an attacker-controlled Git repository where the .git/config file has been altered to set core.fsmonitor to an external filesystem-monitor helper managed by the attacker. As a result, when Codex collects repository metadata, it could trigger the execution of the attacker's code outside of the application sandbox, allowing unauthorized access to the user's system. This may lead to the ability to manipulate, view, or delete files and access sensitive resources within the user's account.

Affected Version(s)

Codex CLI Windows 0.102.0 <= 0.130.0

Codex Desktop (Microsoft Store package) Windows 26.304.38.0 <= 26.513.4821.0

Codex Desktop macOS 260202.0859 <= 26.513.31313

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

System Software and Security Lab, Fudan University
.