Executive brief
OpenAI Codex Desktop for Windows and macOS automatically inspects Git repository metadata when users open a workspace. An attacker can craft a malicious .git/config file with filter settings that causes Git to execute arbitrary code with the signed-in user's full privileges, bypassing Codex's security sandbox. The attacker can read, modify, or delete files and steal credentials—no user interaction or approval is required.
Technical details
The vulnerability is a local code execution flaw in OpenAI Codex Desktop's workspace initialization. When a workspace is opened, Codex automatically runs Git commands to inspect repository metadata and working-tree status. An attacker can place a crafted .git/config file (via a tar/zip archive or shared repository export) that defines malicious clean or process filters using the attr.tree setting. Git will execute the attacker-controlled command on next inspection, running outside Codex's sandbox and without workspace-trust prompts or command approval. Exploitation requires Git to be installed on the user's PATH and the repository to retain its local .git/config (standard Git clones strip this, but archives or explicit pulls preserve it). The attacker gains file system and credential access as the signed-in user.
Affected products
- OpenAI Codex Desktop all versions prior to patch
Timeline
- 2026-09-01: disclosed