{"data":{"id":"aed351a5-556a-4f33-a657-f3a09cdf3435","title":"CVE-2026-19590: OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations ","summary":"OpenAI Codex Desktop for Windows and macOS has a vulnerability where it automatically runs Git hooks (scripts that execute during Git operations) from a repository's local settings without checking if they're malicious. An attacker can create a specially prepared repository that, when opened in Codex, runs their malicious hook with the user's full permissions, potentially allowing them to steal, modify, or delete files.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19590","publishedAt":"2026-09-01T18:17:40.140Z","cveId":"CVE-2026-19590","cweIds":["CWE-427"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI","OpenAI Codex Desktop"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-01T18:17:40.140Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}