The ZDI advisories do not establish exploitation in the wild.
- supportsZDI-26-649 / CVE-2026-19591
Locator: SRC-ZDI-26-649
The ZDI advisories do not establish exploitation in the wild.
Case · DiggingBeagle record
ZDI disclosed two patched OpenAI Codex vulnerabilities from Pwn2Own: CVE-2026-19590 in configuration handling and CVE-2026-19591 in Git argument/control-sequence handling. Both scored CVSS 7.8 and could execute code as the current user after the victim opened attacker-controlled content or a malicious folder. The advisories do not establish exploitation in the wild.
Locator: SRC-ZDI-26-649
The ZDI advisories do not establish exploitation in the wild.
Locator: SRC-ZDI-26-648
ZDI-26-648 / CVE-2026-19590 describes unsafe configuration handling leading to code execution after attacker-controlled content is opened.
Locator: SRC-ZDI-26-649
ZDI-26-649 / CVE-2026-19591 describes insufficient neutralization of control sequences in Git command arguments, allowing code execution from a malicious folder.
Locator: SRC-ZDI-26-649
ZDI states OpenAI issued updates correcting both vulnerabilities before coordinated public disclosure.
Locator: SRC-ZDI-26-648
Both vulnerabilities carry CVSS 7.8 and allow code execution in the context of the current user.
Locator: SRC-ZDI-26-648
Both vulnerabilities were reported to OpenAI on June 2, 2026 and publicly disclosed in coordinated ZDI advisories on September 10, 2026.
Locator: SRC-ZDI-26-649
CVE-2026-19590 requires the target to visit malicious content or open a malicious file; CVE-2026-19591 requires opening a malicious folder.
DiggingBeagle. “Two Codex malicious-repository flaws could execute code as the current user.” First seen Sep 10, 2026. https://diggingbeagle.com/cases/two-codex-malicious-repository-flaws-could-execute-code-as-the-current-user/
Citation guidanceWhy this archive exists
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.