Update Available for Two OpenAI Codex Package Vulnerabilities on openSUSE Tumbleweed
Advisory openSUSE-SU-2026:11923-1, rated moderate, addresses two separate vulnerabilities in the openai-codex package as it is delivered on the GA media of openSUSE Tumbleweed. The first flaw, CVE-2026-91986, carries a SUSE CVSS v3.1 score of 5.4 and a CVSS v4.0 score of 5.3. The second, CVE-2026-93657, is scored 7.5 under CVSS v3.1 and 8.7 under CVSS v4.0, the higher of the pair. Updated builds are available as openai-codex 0.158.0-1.1, together with the matching bash, fish and zsh completion subpackages. Only openSUSE Tumbleweed installations carrying these packages are listed as affected by the advisory.
The advisory does not publish exploitation details for either issue, so the attack mechanics can only be read from the published CVSS vectors. Both CVEs are described as network reachable with low attack complexity and no privileges required. CVE-2026-91986 additionally requires user interaction and yields limited confidentiality and integrity loss within the same scope. CVE-2026-93657 needs no interaction at all and is rated for high integrity impact with no confidentiality or availability effect, pointing to unauthorised modification rather than data theft or disruption.
Codex is an AI coding agent that generally runs on developer workstations alongside source repositories and build tooling, so an integrity-affecting flaw there touches code that moves downstream. Tumbleweed is a rolling release, so systems that have not synchronised with current GA media remain on the vulnerable build. There is no indication of exploitation in the wild: FIRST EPSS places CVE-2026-91986 at a 0.2% probability of exploitation in the next 30 days and CVE-2026-93657 at 0.4%.
Attack Surface
Endpoint, Supply Chain (Third-party vendors)
Tactics
Execution, Impact, Initial Access
Techniques
- T1195.002 – Compromise Software Supply Chain
- T1059 – Command and Scripting Interpreter
- T1565 – Data Manipulation
SuperPRO's Threat Countermeasures Procedures
- The fix published in openSUSE-SU-2026:11923-1 is openai-codex 0.158.0-1.1, delivered on Tumbleweed GA media via 'zypper dup' or 'zypper install openai-codex-0.158.0-1.1', with openai-codex-bash-completion, openai-codex-fish-completion and openai-codex-zsh-completion shipped at the same 0.158.0-1.1 build.
- The installed build on a given host is shown by 'rpm -q openai-codex', and any result below 0.158.0-1.1 is the version openSUSE-SU-2026:11923-1 identifies as carrying CVE-2026-91986 and CVE-2026-93657.
- openSUSE-SU-2026:11923-1 lists openai-codex-bash-completion, openai-codex-fish-completion and openai-codex-zsh-completion as affected alongside the main package, and all four are fixed only at build 0.158.0-1.1 on openSUSE Tumbleweed.
- Rebuild or refresh any golden images, containers or Tumbleweed GA media snapshots that bundle an openai-codex build older than 0.158.0-1.1, so new deployments do not reintroduce the vulnerable package.
- The fixed packages named in openSUSE-SU-2026:11923-1 reach hosts through the Tumbleweed GA media repository, so a metadata refresh with 'zypper ref' is what makes the 0.158.0-1.1 build visible to systems whose repository data predates the advisory.
- Advisory openSUSE-SU-2026:11923-1 is the single reference covering both CVE-2026-91986 and CVE-2026-93657, so remediation tracking against that advisory id closes both flaws with one openai-codex package update rather than two separate changes.