LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-19593

Published
CVSS9.8
Severitycritical
WeaknessCWE-15
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared reposi

References

← Back to the CVE Tracker

Our coverage of CVE-2026-19593

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-19593.