Case · DiggingBeagle record

Two Codex malicious-repository flaws could execute code as the current user

ZDI disclosed two patched OpenAI Codex vulnerabilities from Pwn2Own: CVE-2026-19590 in configuration handling and CVE-2026-19591 in Git argument/control-sequence handling. Both scored CVSS 7.8 and could execute code as the current user after the victim opened attacker-controlled content or a malicious folder. The advisories do not establish exploitation in the wild.

First seen
Sep 10, 2026
Case kind
vulnerability
AI role
AGAINST AI
Claims
7

Reconstruction

Claims & evidence

reported findingsupported

The ZDI advisories do not establish exploitation in the wild.

reported findingsupported

ZDI-26-648 / CVE-2026-19590 describes unsafe configuration handling leading to code execution after attacker-controlled content is opened.

  • supports
    ZDI-26-648 / CVE-2026-19590

    Locator: SRC-ZDI-26-648

    ZDI-26-648 / CVE-2026-19590 describes unsafe configuration handling leading to code execution after attacker-controlled content is opened.
reported findingsupported

ZDI-26-649 / CVE-2026-19591 describes insufficient neutralization of control sequences in Git command arguments, allowing code execution from a malicious folder.

  • supports
    ZDI-26-649 / CVE-2026-19591

    Locator: SRC-ZDI-26-649

    ZDI-26-649 / CVE-2026-19591 describes insufficient neutralization of control sequences in Git command arguments, allowing code execution from a malicious folder.
reported findingsupported

ZDI states OpenAI issued updates correcting both vulnerabilities before coordinated public disclosure.

  • supports
    ZDI-26-649 / CVE-2026-19591

    Locator: SRC-ZDI-26-649

    ZDI states OpenAI issued updates correcting both vulnerabilities before coordinated public disclosure.
reported findingsupported

Both vulnerabilities carry CVSS 7.8 and allow code execution in the context of the current user.

  • supports
    ZDI-26-648 / CVE-2026-19590

    Locator: SRC-ZDI-26-648

    Both vulnerabilities carry CVSS 7.8 and allow code execution in the context of the current user.
reported findingsupported

Both vulnerabilities were reported to OpenAI on June 2, 2026 and publicly disclosed in coordinated ZDI advisories on September 10, 2026.

  • supports
    ZDI-26-648 / CVE-2026-19590

    Locator: SRC-ZDI-26-648

    Both vulnerabilities were reported to OpenAI on June 2, 2026 and publicly disclosed in coordinated ZDI advisories on September 10, 2026.
reported findingsupported

CVE-2026-19590 requires the target to visit malicious content or open a malicious file; CVE-2026-19591 requires opening a malicious folder.

  • supports
    ZDI-26-649 / CVE-2026-19591

    Locator: SRC-ZDI-26-649

    CVE-2026-19590 requires the target to visit malicious content or open a malicious file; CVE-2026-19591 requires opening a malicious folder.

Implications

What remains unknown

  • Public advisories provide limited detail on affected version ranges and do not quantify exposed installations.

Cite this record

DiggingBeagle. “Two Codex malicious-repository flaws could execute code as the current user.” First seen Sep 10, 2026. https://diggingbeagle.com/cases/two-codex-malicious-repository-flaws-could-execute-code-as-the-current-user/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.