CVE-2026-19590

7.3

OpenAI · Codex Desktop

OpenAI Codex Desktop for Windows and macOS improperly trusts local Git configuration, allowing malicious repositories to execute unauthorized code via Git hooks upon opening.

Executive summary

A high-severity vulnerability in OpenAI Codex Desktop allows local attackers to achieve arbitrary code execution by tricking users into opening a specially crafted Git repository.

Vulnerability

The application is vulnerable to an uncontrolled search path element (CWE-427) where automated Git operations trust the local core.hooksPath setting. This allows an attacker to force the application to execute arbitrary hooks under the user's privilege level without consent when a malicious repository is opened.

Business impact

Successful exploitation grants an attacker the ability to execute arbitrary commands on the host machine with the privileges of the logged-in user. This could result in unauthorized file access, data exfiltration, or the installation of persistent malware. Given the CVSS score of 7.3, this represents a significant risk to endpoint security and corporate intellectual property.

Remediation

Immediate Action: Upgrade to OpenAI Codex Desktop version 26.519.22136 for macOS, or version 26.519.21041 (Microsoft Store package 26.519.2081.0) for Windows immediately.

Proactive Monitoring: Audit local machine logs for unexpected process execution originating from the Codex Desktop application process.

Compensating Controls: Advise users to avoid opening Git repositories from untrusted or unknown sources until the application has been patched.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability poses a critical risk to endpoints where Codex Desktop is utilized for repository management. Organizations must prioritize the deployment of the provided patches to all affected workstations. Failure to update the software leaves users vulnerable to malicious hooks that can bypass standard security controls and compromise the host environment.

More OpenAI CVEs

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.3 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section, early-warning entry

Sources

Originally found and disclosed by Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)., per the CVE Program record.