Root cause
Automated repository operations honored repository-local Git hook configuration outside the intended command-approval boundary.
Demonstrated impact
The vendor confirms possible user-privilege code execution when specially prepared local repository configuration is preserved. An ordinary Git clone does not preserve that configuration.
Lessons for review
- Treat repository-local execution settings as untrusted input.
- Apply execution policy to background tooling as well as user-visible agent commands.
Award and evidence
The successful second-round entry earned USD 20,000. The advertised first-round maximum and researcher’s other event entries are not this award. Event rules explicitly denominate prizes in US currency; cash settlement is unverified.
Matched organizer result to the credited team, product and distinct CVE in the vendor CNA and Pwn2Own-tagged ZDI advisory; checked official currency and one-entry-per-target rules.
- Competition award, not an ordinary vendor bounty or a team’s total earnings.
- Original organizer submission and cash-transfer dates are unknown.
- Public demonstration, later vendor notification and technical publication are distinct events.
Recorded timeline
- Published
- 2026-09-01explicit · Vendor-authored technical CNA publication. ZDI published its advisory on September 10.
- Public Disclosure
- 2026-05-15explicit · Public competition demonstration and result, before technical CNA publication.
- Awarded
- 2026-05-15explicit · Individual-entry award reported in the day’s results.
- Award Announced
- 2026-05-15explicit
Sources and provenance
- OpenAI CNA record for CVE-2026-19590 OpenAI CNA, distributed through the CVE Program · reviewed 2026-10-02
- Pwn2Own Berlin 2026 daily results Dustin Childs / Zero Day Initiative · reviewed 2026-10-02
- Pwn2Own Berlin 2026 rules Trend Micro Zero Day Initiative · reviewed 2026-10-02
- ZDI-26-648 Codex advisory Zero Day Initiative · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.