Source · DiggingBeagle record
ZDI-26-649 / CVE-2026-19591
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Claim-level citations (4)
- supportsTwo Codex malicious-repository flaws could execute code as the current user: The ZDI advisories do not establish exploitation in the wild.
SRC-ZDI-26-649
- supportsTwo Codex malicious-repository flaws could execute code as the current user: ZDI-26-649 / CVE-2026-19591 describes insufficient neutralization of control sequences in Git command arguments, allowing code execution from a malicious folder.
SRC-ZDI-26-649
- supportsTwo Codex malicious-repository flaws could execute code as the current user: ZDI states OpenAI issued updates correcting both vulnerabilities before coordinated public disclosure.
SRC-ZDI-26-649
- supportsTwo Codex malicious-repository flaws could execute code as the current user: CVE-2026-19590 requires the target to visit malicious content or open a malicious file; CVE-2026-19591 requires opening a malicious folder.
SRC-ZDI-26-649
Cite this record
DiggingBeagle. “ZDI-26-649 / CVE-2026-19591.” https://diggingbeagle.com/sources/zdi-26-649-cve-2026-19591/
Citation guidance