Hackers can steal your GitHub tokens via OpenAI Codex using nothing more than a sneaky branch name


  • A Carefully Crafted Branch Name Can Steal Your GitHub Auth Token
  • Unicode spaces hide malicious payloads from human eyes in plain sight
  • Attackers can automate token theft between multiple users sharing a repository

Security researchers have discovered a command injection vulnerability in OpenAI’s Codex cloud environment that allowed attackers to steal GitHub authentication tokens using nothing more than a carefully crafted branch name.

Research by BeyondTrust Phantom Labs found that the vulnerability is due to improper input sanitization in the way Codex processed GitHub branch names during task execution.



Leave a Comment

Your email address will not be published. Required fields are marked *