Impact
OpenAI Codex Desktop for Windows and macOS allows execution of attacker‑controlled Git hooks because the application trusts the repository’s local core.hooksPath setting. A malicious hook placed in the designated directory runs outside Codex’s command sandbox with the user’s privileges, enabling the attacker to read, modify, or delete user files and access other resources. The flaw requires a repository that preserves a .git/config file pointing core.hooksPath to an attacker‑controlled directory; simple Git clones do not provide this configuration and therefore are not exploitable directly.
Affected Systems
The vulnerability affects all versions of OpenAI Codex Desktop prior to application version 26.519.22136 on macOS and prior to 26.519.21041 on Windows, including the Microsoft Store package version 26.519.2081.0. Any installation of Codex Desktop falling within these version ranges is susceptible.
Risk and Exploitability
The flaw represents a high‑severity risk due to the potential for arbitrary code execution with full user privileges. No EPSS score is available, and the vulnerability is currently not listed in the CISA KEV catalog. It can be exploited by delivering a crafted repository archive or by copying a repository directory that retains the attacker‑supplied configuration. Because the execution occurs outside the sandbox, the impact is broad and can compromise system integrity and confidentiality.
OpenCVE Enrichment