Security Researchers Expose Vulnerability in OpenAI Codex That Could Leak GitHub Tokens
Security researchers from BeyondTrust Phantom Labs have uncovered a critical vulnerability in OpenAI’s Codex environment that could have allowed attackers to steal GitHub authentication tokens from...
Security researchers from BeyondTrust Phantom Labs have uncovered a critical vulnerability in OpenAI’s Codex environment that could have allowed attackers to steal GitHub authentication tokens from developers using the AI coding agent.
The flaw originated from improper input validation during Codex’s processing of GitHub branch names during task execution. Researchers demonstrated that a malicious branch name could contain hidden commands, allowing attackers to execute code inside the agent’s cloud environment. Once inside, the attacker could retrieve GitHub OAuth tokens tied to repositories, workflows, and private source code.
Because Codex operates with access to connected repositories, the potential impact extends beyond a single user. Phantom Labs found that the attack could be automated to compromise multiple users interacting within a shared repository environment.
The vulnerability affected several Codex interfaces, including the ChatGPT website, Codex CLI, Codex SDK, and the Codex IDE extension. Researchers also identified techniques that could hide malicious commands using Unicode characters, making the exploit harder to detect.
BeyondTrust noted that AI coding agents increasingly function as privileged systems with direct access to code and infrastructure, creating new security risks if inputs are not strictly validated.
Phantom Labs reported the issue to OpenAI through responsible disclosure, and the company has since patched the vulnerability.



No Comment! Be the first one.