Impact
The Codex CLI and Desktop applications automatically read the local .git/config file of any repository that is opened or used. If that configuration contains a malicious core.fsmonitor entry, Git will invoke the specified filesystem‑monitor helper outside the Codex sandbox and without user approval, allowing attacker‑controlled code to run with the user’s privileges. This vulnerability, a form of configuration-based remote code execution, enables the attacker to read, modify, or delete files or otherwise compromise the user’s environment.
Affected Systems
Affected products are OpenAI Codex CLI, Codex Desktop for Windows, macOS, and Linux. The vendor’s official solution requires upgrading Codex CLI to version 0.131.0 or later, upgrading Codex Desktop for macOS to application version 26.519.22136 or later, and upgrading Codex Desktop for Windows to application version 26.519.21041 (Microsoft Store package 26.519.2081.0) or later. Until these updates are applied, the vulnerability remains present in those releases.
Risk and Exploitability
No CVSS score is provided and the EPSS score is unavailable, but the vulnerability is listed as not in the CISA KEV catalog. The flaw allows full remote code execution with the privileges of the logged‑in user. Exploitation requires an attacker to supply a repository that preserves a malicious .git/config; ordinary Git clone operations do not retain such a configuration. Given the high impact of successful exploitation, the risk is deemed high and action is urgently recommended.
OpenCVE Enrichment