Hackers can steal your GitHub tokens through OpenAI’s Codex using nothing more than a sneaky branch name


  • A carefully crafted branch name can steal your GitHub authentication token
  • Unicode spaces hide malicious payloads from human eyes in plain sight
  • Attackers can automate token theft across multiple users sharing a repository

Security researchers have discovered a command injection vulnerability in OpenAI’s Codex cloud environment that allowed attackers to steal GitHub authentication tokens using nothing more than a carefully crafted branch name.

Investigations by BeyondTrust Phantom Labs found that the vulnerability stems from incorrect input sanitization in how Codex handled GitHub branch names during task execution.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top