Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 562 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7.3) | 0.11% | — | Openai Codex CLIAIOpenai Codex DesktopAIGit-scm GITAI | 1/9/2026 | 2/9/2026 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an… | |
| En análisis | Alta (8.8) | 0.30% | — | Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI | 1/9/2026 | 2/9/2026 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex… | |
| Pendiente de análisis | Crítica (9.8) | 6.6% | — | Openai Codex CLIAI | 14/4/2026 | 5/7/2026 | A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads project-local .env and… | |
| Aplazada | Alta (8.6) | 0.87% | — | Openai Codex CLIAIOpenai Codex IDE ExtensionAI | 22/9/2025 | 17/6/2026 | Codex CLI is a coding agent from OpenAI that runs locally. In versions 0.2.0 to 0.38.0, due to a bug in the sandbox configuration logic, Codex CLI could treat a model-generated cwd as the sandbox’s writable root, including paths outside of the folder where the user started their session. This logic bypassed the… | |
| Aplazada | Alta (8.8) | 0.84% | — | Codex CLIAI | 13/8/2025 | 17/6/2026 | Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due to symlinks being followed outside the allowed current working directory. | |
| Aplazada | Media (4.1) | 0.19% | — | Openai Codex CLIAIRipgrepAI | 25/7/2025 | 17/6/2026 | OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag. |