CVE-2026-19591 - OpenAI Codex Command Injection Vulnerability
Brief
CVE ID : CVE-2026-19591
Published : Sept. 1, 2026, 6:17 p. m.
- 59 minutes ago
Description : OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself.
If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting user approval. On macOS and Linux, exploitation additionally requires separately installed PowerShell Core (pwsh) to be invoked. If filesystem protections permit the write, the command can modify Codex's configuration.
