Latest CVEs
The 9 most recently published vulnerabilities affecting openai.
- CVE-2026-19592OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting....7.3
- CVE-2026-19593OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacke...9.8
- CVE-2026-19591OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's...8.8
- CVE-2026-19590OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an att...7.3
- CVE-2026-14898The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a con...6.5
- BDU:2025-14772Уязвимость веб-браузеров Atlas и Comet, связанная с недостаточной защитой служебных данных, позволяющая нарушителю проводить спуфинг-атаки7.1
- CVE-2025-54558OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.4.1
- CVE-2025-7021OpenAI Operator - API Spoofing through Locking Operator on FullScreen6.5
- CVE-2025-43714The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most mode...6.5