Code Execution Vulnerability in OpenAI Codex for Windows and macOS
CVE-2026-19593

Currently unrated

Key Information:

Vendor

Openai

Vendor
CVE Published:
1 September 2026

What is CVE-2026-19593?

A flaw in OpenAI Codex for Windows and macOS allows an attacker to execute arbitrary programs through a maliciously crafted Git repository. When users launch a workspace containing a repository with a compromised .git/config file, exploitation can occur without user interaction. This occurs because the attr.tree setting combined with clean or process filters can trigger the execution of attacker-controlled code outside of Codex's secure environment. Users are at risk of unauthorized access to files, modification of content, and potential exposure of sensitive information like credentials. The exploitation requires the presence of Git in the system path and the user to interact with the manipulated repository.

Affected Version(s)

Codex Desktop (Microsoft Store package) Windows 26.304.38.0 <= 26.513.4821.0

Codex Desktop macOS 260202.0859 <= 26.513.31313

Codex Desktop Windows 26.304.38 <= 26.513.40821

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Satoki Tsuji (@satoki00) / Ikotas Labs, Inc.
.