logo

OpenAI Codex Vulnerability Allowed Attackers to Steal GitHub Tokens

ID: e34fdb59-8cfb-5d12-adaf-767e07d25de1

STIX ID: report--e34fdb59-8cfb-5d12-adaf-767e07d25de1

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

BeyondTrust Phantom Labs disclosed a critical command-injection vulnerability in OpenAI Codex that abused hidden Unicode (ideographic space) in GitHub branch names to execute commands and reveal GitHub OAuth tokens. The flaw impacted the ChatGPT website, Codex SDK, and developer extensions and also exposed tokens stored locally (auth.json); the issue was reported in December 2025 and patched by OpenAI between December 2025 and February 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.