Semicolon in a Codex branch name leaked GitHub token via command injection
BeyondTrust's Phantom Labs disclosed a critical flaw in OpenAI Codex: an unsanitized branch name was passed into a shell command, letting attackers extract a GitHub OAuth token stored in cleartext in the remote URL. The bug affected the ChatGPT web interface, CLI, SDK and IDE extension; OpenAI fixed it after roughly six weeks of hardening.
- Branch names with ;, &&, | or $() were executed as shell syntax without sanitization
- The GitHub OAuth token sat in cleartext in the remote URL and surfaced in agent output
- The flaw reached every Codex surface: ChatGPT, CLI, SDK and IDE extension
- Teleport found 70% of firms give AI agents more access than a human doing the same task
Read next
Security