vulns.co
/
GKData.io MCP

AIAI integration boundaries · 2 min read

Codex metadata collection trusted repository execution helpers

ZDI awarded Doyensec USD 10,000 for this distinct Pwn2Own Berlin entry.

Read the primary source AIAI integration boundariesReviewed 2026-10-02

Root cause

Background metadata collection honored a repository-controlled filesystem-monitor helper without applying the intended approval and sandbox boundaries.

Demonstrated impact

The vendor confirms possible user-privilege code execution from preserved local repository settings. An ordinary Git clone does not preserve the required configuration.

Lessons for review

  • Make background metadata collection independent of untrusted execution settings.
  • Review ambient tool configuration as part of the application’s authority model.

Award and evidence

USD 10,000Competition Award · Organizer Confirmed

Organizer records a collision with a vendor-known issue and a reduced USD 10,000 award. This is not a USD 40,000 first-round win. The vendor also credits Fudan researchers, without assigning them this competition award. Event rules explicitly denominate prizes in US currency; cash settlement is unverified.

Matched organizer result to the credited team, product and distinct CVE in the vendor CNA and Pwn2Own-tagged ZDI advisory; checked official currency and one-entry-per-target rules.

  • Competition award, not an ordinary vendor bounty or a team’s total earnings.
  • Original organizer submission and cash-transfer dates are unknown.
  • Public demonstration, later vendor notification and technical publication are distinct events.
  • The ZDI vendor-report date follows the CNA publication; it is preserved only as a qualified note, not treated as an original report date.

Recorded timeline

Published
2026-09-01explicit · Vendor-authored technical CNA publication. ZDI published its advisory on September 10.
Public Disclosure
2026-05-14explicit · Public competition demonstration and result, before technical CNA publication.
Awarded
2026-05-14explicit · Individual-entry award reported in the day’s results.
Award Announced
2026-05-14explicit

Sources and provenance

  1. OpenAI CNA record for CVE-2026-19592 OpenAI CNA, distributed through the CVE Program · reviewed 2026-10-02
  2. Pwn2Own Berlin 2026 daily results Dustin Childs / Zero Day Initiative · reviewed 2026-10-02
  3. Pwn2Own Berlin 2026 rules Trend Micro Zero Day Initiative · reviewed 2026-10-02
  4. ZDI-26-650 Codex advisory Zero Day Initiative · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software