logo

OpenAI Codex Command Injection Vulnerability Let Attackers Steal GitHub User Access Tokens

ID: 5318d3e9-ca8d-5c3a-b8cb-fcc56bb93a27

STIX ID: report--5318d3e9-ca8d-5c3a-b8cb-fcc56bb93a27

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive Summary:** BeyondTrust researchers discovered a critical command-injection vulnerability in OpenAI Codex that permitted attackers to inject shell commands via GitHub branch names and steal GitHub OAuth/installation tokens (including from local auth files), enabling lateral movement and widespread compromise through automated malicious branches; the flaw affected web, CLI, SDK, and IDE integrations and was patched after responsible disclosure in January 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.