Urgent.News

What's breaking now, across thousands of outlets.

Tech

A semicolon in a Codex branch name leaked its GitHub token. Scope decided the damage

A branch name with a semicolon in it was enough to pull a GitHub OAuth token out of OpenAI's Codex, according to a DevOps.com write-up of a critical flaw that BeyondTrust's Phantom Labs disclosed in March. OpenAI has fixed it. For teams wiring agents into their delivery pipelines, the bug matters less than the token. Its scope decided how far a single injected command could reach. The mechanism…

A seemingly innocuous semicolon in a branch name of a GitHub repository has proven to be a critical vulnerability, according to a report from DevOps.com. The flaw, disclosed by BeyondTrust's Phantom Labs in March, allows malicious actors to extract a GitHub OAuth token from OpenAI's Codex. OpenAI has since patched the issue, but the potential impact remains significant.

The vulnerability arises when Codex generates a task container and passes the branch name into a shell command without sanitizing it first. This oversight allows malicious code to be injected and executed. Bash interprets characters such as semicolons, &&, |, $(), and backticks as shell syntax rather than part of the branch name.

In a proof of concept, researchers demonstrated how the token could be extracted by appending a second command to the git command that writes the output of git remote get-url origin to a file. The bug can affect every surface of Codex, including the web interface, CLI, SDK, and IDE extension. According to a survey by Teleport, organizations that over-provision AI systems experience 4.5 times more security incidents than those enforcing least privilege.

The report also found that 70% of organizations give AI agents more access than a human doing the same task, and 67% still use static credentials for AI systems. The article recommends hardening the input path by stopping the building of shell strings and using allowlists, quoting values, and treating input as hostile. Moving the token out of the remote URL and into a credential helper or git config header also reduces the risk.

Limiting the scope and lifetime of the token, requesting visibility into the agent's credential capabilities, and using short-lived, single-use credentials are additional measures suggested to mitigate the impact of this vulnerability.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Terminal Setup

Default terminal ugly and slow. Fix in 10 minutes. Step 1: Pick Better Terminal Ditch default CMD or Mac terminal. Windows: Windows Terminal Mac: Ghostty or iTerm2 Linux: Alacritty or Kitty Step 2…

How I Built a Simple Brat-Style Text Image Generator for the Web

Not every visual project needs a complicated design application. Sometimes you have a short phrase, caption, or idea and simply want to turn it into a clean image that can be shared online.

  • Brat-style generator simplifies web-based image creation
  • Users input text, customize options, generate visuals
  • Project teaches web development fundamentals

More from Saturday 3 October →