Skip to content
OpenAICVE-2026-19590

OpenAI Codex Desktop: uncontrolled search path

High7.3CVE-2026-19590 · Published Sep 1, 2026 · updated Sep 3, 2026

OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation.

OpenAI advisory

Affected versions

PackageAffectedFixed in
Codex Desktop
Product
>= 260202.0859, <= 26.513.31313No fix yet
>= 26.304.38, <= 26.513.40821No fix yet
Codex Desktop (Microsoft Store package)
Product
>= 26.304.38.0, <= 26.513.4821.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-427

More OpenAI advisories

All OpenAI
Advisory
OpenAI Codex CLI for Windows
High8.8Sep 1
OpenAI Codex CLI for Windows
High7.3Sep 1
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata...
Critical9.8Sep 1
OpenAI Codex desktop app for macOS: information disclosure
Medium6.5Jul 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.