Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19593

Quick assessment

Affected
OpenAI Codex Desktop
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenAI Codex Desktop是美国OpenAI公司的一款集成人工智能的编程辅助桌面客户端。 OpenAI Codex Desktop for macOS 26.513.31313及之前版本、OpenAI Codex Desktop for Windows 26.513.40821及之前版本存在配置错误漏洞,该漏洞源于打开工作区时自动检查Git元数据和工作树状态,当工作区包含攻击者控制的.git/config文件时,attr.tree设置和配置的clean或process过滤器可导致Git运行攻

AI Predicted 6.6 Difficulty: Moderate EPSS 0.29% · P21

Affected Version Matrix 6

VendorProduct Version RangeStatus
OpenAI Codex Desktop 260202.0859≤ 26.513.31313 affected
26.519.22136 unaffected
26.304.38≤ 26.513.40821 affected
26.519.21041 unaffected
OpenAI Codex Desktop (Microsoft Store package) 26.304.38.0≤ 26.513.4821.0 affected
26.519.2081.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19593

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
系统设置或配置在外部可控制
Source: CVE Program / CVE List V5
Vulnerability Title
OpenAI Codex Desktop 配置错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenAI Codex Desktop是美国OpenAI公司的一款集成人工智能的编程辅助桌面客户端。 OpenAI Codex Desktop for macOS 26.513.31313及之前版本、OpenAI Codex Desktop for Windows 26.513.40821及之前版本存在配置错误漏洞,该漏洞源于打开工作区时自动检查Git元数据和工作树状态,当工作区包含攻击者控制的.git/config文件时,attr.tree设置和配置的clean或process过滤器可导致Git运行攻
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenAI Codex Desktop 260202.0859 ~ 26.513.31313 -
OpenAI Codex Desktop 26.304.38 ~ 26.513.40821 -
OpenAI Codex Desktop (Microsoft Store package) 26.304.38.0 ~ 26.513.4821.0 -

II. Public POCs for CVE-2026-19593

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19593

登录查看更多情报信息。

Vendor Pages for CVE-2026-19593 (1)

Same Patch Batch · OpenAI · 2026-09-01 · 4 CVEs total

CVE-2026-19591 OpenAI Codex CLI 输入验证错误漏洞
CVE-2026-19592 OpenAI Codex CLI 配置错误漏洞
CVE-2026-19590 OpenAI Codex Desktop 权限许可和访问控制问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-19593

No comments yet


Leave a comment