{"data":{"id":"fc7d4023-54cf-486f-9d52-ef4dd105700e","title":"CVE-2026-19593: OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user open","summary":"OpenAI Codex Desktop for Windows and macOS automatically checked Git metadata (version control system files) when opening a workspace, which could allow an attacker to run malicious code if the repository contained a specially crafted .git/config file (Git's configuration file). This malicious code would run with the user's full permissions outside of Codex's security protections, potentially letting the attacker read, modify, or delete files and steal credentials.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19593","publishedAt":"2026-09-01T18:17:40.480Z","cveId":"CVE-2026-19593","cweIds":["CWE-15"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI Codex Desktop"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-01T18:17:40.480Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}