OpenAI Codex had a critical command injection flaw: unsanitized branch names allowed GitHub OAuth token theft (opens in new tab)
BeyondTrust Phantom Labs disclosed a critical command injection vulnerability in OpenAI Codex that allowed attackers to steal GitHub OAuth tokens through unsanitized branch names. The flaw affected ChatGPT, Codex CLI, SDK, and IDE extensions, and could scale into automated supply chain attacks via poisoned GitHub branches.
Read the original article