Intel

AIKIDO-2026-960660

@openai/codex is vulnerable to External Control of System or Configuration Setting

External Control of System or Configuration SettingCVE-2026-19592 Published Today

73

High Risk

This Affects:

JS@openai/codex
0.1.4160940 - 0.130.0
Fixed in 0.131.0
Are you affected? Scan for Free

TL;DR

Codex collects Git repository metadata without disabling the repository-local core.fsmonitor setting. A repository delivered with a crafted .git/config can point core.fsmonitor at an attacker-controlled filesystem-monitor helper. When Codex reads metadata or status for that repository, Git executes the helper outside the sandbox, giving code execution with the user's privileges. The fix runs Git metadata commands with the fsmonitor configuration disabled.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Codex opens or collects metadata for a repository delivered with an attacker-controlled .git/config that a plain clone would not preserve.

Background info

@openai/codex is vulnerable to External Control of System or Configuration Setting in versions 0.1.4160940 - 0.130.0.

How to fix this

Upgrade the @openai/codex library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform