chiprook
← Security
SecurityOctober 3, 2026, 17:24

Semicolon in a Codex branch name leaked GitHub token via command injection

BeyondTrust's Phantom Labs disclosed a critical flaw in OpenAI Codex: an unsanitized branch name was passed into a shell command, letting attackers extract a GitHub OAuth token stored in cleartext in the remote URL. The bug affected the ChatGPT web interface, CLI, SDK and IDE extension; OpenAI fixed it after roughly six weeks of hardening.

Semicolon in a Codex branch name leaked GitHub token via command injection
#OpenAI#Codex#GitHub
Read next
Security

Researchers escape OpenAI Codex sandbox to run commands on host

Security

Codex Desktop flaw let untrusted code read auth tokens from shared memory

Software

Codex CLI 0.158: approval for elevated commands and MCP OAuth client secrets

Security

Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI plugins