Feeds.4Sysops Command Injection Vulnerability in OpenAI Codex Exposes GitHub Tokens
Article Content
- •A critical command injection vulnerability in OpenAI Codex exposes GitHub tokens.
- •The flaw allows attackers to inject commands via the GitHub branch name parameter.
- •OpenAI has issued a hotfix to remediate the vulnerability.
BeyondTrust Phantom Labs discovered a command injection vulnerability in OpenAI's Codex, which exposed sensitive GitHub credential data. The flaw exists within the task creation HTTP request, enabling attackers to inject arbitrary commands via the GitHub branch name parameter. This vulnerability could lead to the theft of GitHub User Access Tokens, affecting the ChatGPT website, Codex CLI, Codex SDK, and Codex IDE Extension. OpenAI confirmed the investigation and issued a hotfix to remediate the issue. The vulnerability was disclosed through BugCrowd, and all reported issues have since been addressed. The exploit can scale to compromise multiple users in a shared environment, raising significant security concerns for organizations using these tools.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Common questions
What systems are affected by the vulnerability?
What steps has OpenAI taken to address the issue?
How can organizations protect themselves from this vulnerability?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…