LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-19591

Published
CVSS8.8
Severityhigh
WeaknessCWE-150
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting user approval. On macOS and Linux, exploitation additionally requires separately installed PowerShell Core (pwsh) to be invoked. If filesystem protections permit the write, the command can modify Codex's configuration. If Codex later loads the modified configuration, it can launch an attacker-con

References

← Back to the CVE Tracker

Our coverage of CVE-2026-19591

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-19591.