CVE-2026-19590CWE-427

CVE-2026-19590

High · published September 1, 2026

CVSS v3.1
7.3
EPSS
0%
Percentile
1.1
In the wild
Unconfirmed
What it is

OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation.

The record
Technical detail
CVSS v3.1
7.3 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00103 · 1.1th percentile
Weakness
CWE-427 · Uncontrolled Search Path Element
Published
2026-09-01T22:17Z
References (1)
EPSS history
Timeline
  • 03 SEP 03:28Z
    EPSS moved — → 0%
    epss
  • 01 SEP 17:04Z
    OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local…
    cvelistv5