Source · DiggingBeagle record
ZDI-26-648 / CVE-2026-19590
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Claim-level citations (3)
- supportsTwo Codex malicious-repository flaws could execute code as the current user: ZDI-26-648 / CVE-2026-19590 describes unsafe configuration handling leading to code execution after attacker-controlled content is opened.
SRC-ZDI-26-648
- supportsTwo Codex malicious-repository flaws could execute code as the current user: Both vulnerabilities carry CVSS 7.8 and allow code execution in the context of the current user.
SRC-ZDI-26-648
- supportsTwo Codex malicious-repository flaws could execute code as the current user: Both vulnerabilities were reported to OpenAI on June 2, 2026 and publicly disclosed in coordinated ZDI advisories on September 10, 2026.
SRC-ZDI-26-648
Cite this record
DiggingBeagle. “ZDI-26-648 / CVE-2026-19590.” https://diggingbeagle.com/sources/zdi-26-648-cve-2026-19590/
Citation guidance