logo

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

ID: 22c5afcf-2c0f-5d21-990a-45a392aa1d41

STIX ID: report--22c5afcf-2c0f-5d21-990a-45a392aa1d41

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-03-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Check Point and BeyondTrust disclosed serious vulnerabilities in OpenAI products: a ChatGPT runtime weakness that used a covert DNS channel to exfiltrate user conversations and could enable remote command execution, and a Codex command injection that could steal GitHub tokens and execute payloads in code-review containers; both were responsibly disclosed and patched in early 2026 with no confirmed malicious exploitation reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.