Hackers can steal your GitHub tokens through OpenAI’s Codex using nothing more than a sneaky branch name




  • A carefully crafted branch name can steal your GitHub authentication token
  • Unicode spaces hide malicious payloads from human eyes in plain sight
  • Attackers can automate token theft across multiple users sharing a repository

Security researchers have discovered a command injection vulnerability in OpenAI’s Codex cloud environment that allowed attackers to steal GitHub authentication tokens using nothing more than a carefully crafted branch name.

Research from BeyondTrust Phantom Labs found the vulnerability stems from improper input sanitization in how Codex processed GitHub branch names during task execution.


https://cdn.mos.cms.futurecdn.net/2BXK9rhzJj3TYVMotiBpk4-1920-80.png



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img