≈ the.bay.news

A semicolon in a Codex branch name leaked its GitHub token. Scope decided the damage

DEV Community
A semicolon in a Codex branch name leaked its GitHub token. Scope decided the damage
BeyondTrust's Phantom Labs found that OpenAI Codex passed branch names into a shell without sanitizing them, so a single semicolon could exfiltrate the task's GitHub OAuth token. The bug is fixed, but agents still commonly hold over-scoped, long-lived credentials, and that is what made it dangerous.

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.