Hackers can steal your GitHub tokens through the OpenAI Codex using nothing more than a sneaky branch name


  • A carefully crafted branch name can steal your GitHub auth token
  • Unicode spaces hide malicious payloads from human eyes
  • Attackers can automate token theft between multiple users sharing a repository

Security researchers discovered a command injection vulnerability in OpenAI’s Codex cloud environment that allowed attackers to steal GitHub authentication tokens using nothing more than a carefully crafted branch name.

Research by BeyondTrust Phantom Labs found that the vulnerability stemmed from improper input checking in the way Codex handled GitHub branch names when running tasks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top