Threats Tagged 'cve-2026-19590'
View all threats tagged with 'cve-2026-19590'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-19590'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19590: CWE-427: Uncontrolled Search Path Element in OpenAI Codex DesktopCVE-2026-19590 0 OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation. Join the discussion | CVE Database V5 | 09/01/2026, 17:04:43 UTC Added: 09/01/2026, 17:22:45 UTC |
Showing 1 to 1 of 1 result