Skip to content
Command Injection Vulnerability in OpenAI Codex Exposes GitHub Tokens

Command Injection Vulnerability in OpenAI Codex Exposes GitHub Tokens

First seen 10 Jul 2026, 02:46 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •A critical command injection vulnerability in OpenAI Codex exposes GitHub tokens.
  • •The flaw allows attackers to inject commands via the GitHub branch name parameter.
  • •OpenAI has issued a hotfix to remediate the vulnerability.

BeyondTrust Phantom Labs discovered a command injection vulnerability in OpenAI's Codex, which exposed sensitive GitHub credential data. The flaw exists within the task creation HTTP request, enabling attackers to inject arbitrary commands via the GitHub branch name parameter. This vulnerability could lead to the theft of GitHub User Access Tokens, affecting the ChatGPT website, Codex CLI, Codex SDK, and Codex IDE Extension. OpenAI confirmed the investigation and issued a hotfix to remediate the issue. The vulnerability was disclosed through BugCrowd, and all reported issues have since been addressed. The exploit can scale to compromise multiple users in a shared environment, raising significant security concerns for organizations using these tools.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-08-05
Command injection vulnerability discovered
BeyondTrust reported a critical command injection flaw in OpenAI Codex that exposed GitHub tokens.
BeyondTrust
2026-08-05
OpenAI issues hotfix
OpenAI confirmed the vulnerability and issued a hotfix to address the command injection issue.
BeyondTrust

More articles in this cluster (10)

Common questions

What systems are affected by the vulnerability?
The vulnerability affects the ChatGPT website, Codex CLI, Codex SDK, and Codex IDE Extension.
What steps has OpenAI taken to address the issue?
OpenAI confirmed the vulnerability and issued a hotfix to remediate the command injection flaw.
How can organizations protect themselves from this vulnerability?
Organizations should ensure they are using the updated versions of OpenAI products and monitor for any unusual access patterns.