VYPR

Codex Desktop

by OpenAI

CVEs (3)

  • CVE-2026-19593Sep 1, 2026
    risk 0.00cvss epss

    OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process…

  • CVE-2026-19591Sep 1, 2026
    risk 0.00cvss epss

    OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an…

  • CVE-2026-19590Sep 1, 2026
    risk 0.00cvss epss

    OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an…