« Volver al listado

CVE-2026-19593

Estado: En análisisCrítica (9.8)—

OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user.

Leer descripción completaMostrar menos

Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N sugiere T1190, pero requiere apertura local de workspace con .git/config malicioso; Git ejecuta filtro custom (T1059) permitiendo lectura/modificación de archivos y credenciales del usuario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-19593",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-19593",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-02T17:19:21.924083Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "8f4f43ab-ba69-4d92-aa1d-d772184d6fb7",
      "affectedData": [
        {
          "vendor": "OpenAI",
          "product": "Codex Desktop",
          "versions": [
            {
              "status": "affected",
              "version": "260202.0859",
              "versionType": "custom",
              "lessThanOrEqual": "26.513.31313"
            },
            {
              "status": "unaffected",
              "version": "26.519.22136"
            }
          ],
          "platforms": [
            "macOS"
          ]
        },
        {
          "vendor": "OpenAI",
          "product": "Codex Desktop",
          "versions": [
            {
              "status": "affected",
              "version": "26.304.38",
              "versionType": "custom",
              "lessThanOrEqual": "26.513.40821"
            },
            {
              "status": "unaffected",
              "version": "26.519.21041"
            }
          ],
          "platforms": [
            "Windows"
          ]
        },
        {
          "vendor": "OpenAI",
          "product": "Codex Desktop (Microsoft Store package)",
          "versions": [
            {
              "status": "affected",
              "version": "26.304.38.0",
              "versionType": "custom",
              "lessThanOrEqual": "26.513.4821.0"
            },
            {
              "status": "unaffected",
              "version": "26.519.2081.0"
            }
          ],
          "platforms": [
            "Windows"
          ]
        }
      ]
    }
  ],
  "published": "2026-09-01T18:17:40.480",
  "references": [
    {
      "url": "https://openai.com/codex",
      "source": "8f4f43ab-ba69-4d92-aa1d-d772184d6fb7"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "8f4f43ab-ba69-4d92-aa1d-d772184d6fb7",
      "description": [
        {
          "lang": "en",
          "value": "CWE-15"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself."
    }
  ],
  "lastModified": "2026-09-02T18:19:16.337",
  "sourceIdentifier": "8f4f43ab-ba69-4d92-aa1d-d772184d6fb7"
}