Impact
OpenAI Codex Desktop for macOS and Windows automatically inspects Git metadata when a workspace is opened. If a repository contains attacker‑controlled .git/config with a vulnerable attr.tree setting and a configured clean or process filter, Git can execute an attacker‑supplied program. The program runs outside Codex’s sandbox with the user’s privileges, enabling the attacker to read, modify, or delete files and access user credentials. The vulnerability is a classic example of improper control of code generation and configuration, as documented by CWE‑15.
Affected Systems
Affected systems include OpenAI Codex Desktop for macOS (up to application version 26.518.x) and for Windows (up to application version 26.518.x). The vulnerability specifically impacts installations that allow automatic Git metadata inspection on workspace load, particularly those featuring a preserved .git/config directory.
Risk and Exploitability
The flaw affords direct execution of arbitrary code within the signed‑in user’s environment, representing a high‑severity remote code execution risk. Because exploitation requires the user to open a specially crafted repository and Git must be available on the system path, the attack vector is local but user‑initiated. No EPSS score is available, and the vulnerability is not currently listed in CISA’s KEV catalog. Affected users should treat the issue as a critical security failure pending the vendor patch.
OpenCVE Enrichment