vulns.co
/
GKData.io MCP

INInjection and untrusted input · 2 min read

Codex command approval relied on inconsistent parser semantics

ZDI awarded Compass Security USD 40,000 for this distinct Pwn2Own Berlin entry.

Read the primary source INInjection and untrusted inputReviewed 2026-10-02

Root cause

Command-safety analysis and the invoked shell interpreted control syntax differently, so the approval decision did not consistently describe the resulting operation.

Demonstrated impact

The vendor describes possible code execution with user privileges after untrusted repository instructions are followed. Shell availability and filesystem protections constrain impact; command approval failure does not itself disable the filesystem sandbox.

Lessons for review

  • Keep safety classification consistent with actual command interpretation.
  • Apply independent filesystem restrictions and protect security-sensitive configuration.

Award and evidence

USD 40,000Competition Award · Organizer Confirmed

Single competition entry awarded to the Compass team; individual recipient splits and cash-transfer date are unknown. Event rules explicitly denominate prizes in US currency; cash settlement is unverified.

Matched organizer result to the credited team, product and distinct CVE in the vendor CNA and Pwn2Own-tagged ZDI advisory; checked official currency and one-entry-per-target rules.

  • Competition award, not an ordinary vendor bounty or a team’s total earnings.
  • Original organizer submission and cash-transfer dates are unknown.
  • Public demonstration, later vendor notification and technical publication are distinct events.

Recorded timeline

Published
2026-09-01explicit · Vendor-authored technical CNA publication. ZDI published its advisory on September 10.
Public Disclosure
2026-05-14explicit · Public competition demonstration and result, before technical CNA publication.
Awarded
2026-05-14explicit · Individual-entry award reported in the day’s results.
Award Announced
2026-05-14explicit

Sources and provenance

  1. OpenAI CNA record for CVE-2026-19591 OpenAI CNA, distributed through the CVE Program · reviewed 2026-10-02
  2. Pwn2Own Berlin 2026 daily results Dustin Childs / Zero Day Initiative · reviewed 2026-10-02
  3. Pwn2Own Berlin 2026 rules Trend Micro Zero Day Initiative · reviewed 2026-10-02
  4. ZDI-26-649 Codex advisory Zero Day Initiative · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software