{
  "id": 11017888,
  "title": "A Semicolon in a Branch Name Was All It Took to Steal an AI Agent’s GitHub Token",
  "url": "https://urgent.news/2026/09/30/a-semicolon-in-a-branch-name-was-all-it-took-to-steal-an-ai-agents",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-30T19:35:46.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/a-semicolon-in-a-branch-name-was-all-it-took-to-steal-an-ai-agents-github-token/"
  },
  "original_language": "en",
  "account": "In March, a critical command injection vulnerability was disclosed in OpenAI's Codex, a tool used by AI coding agents to create real containers, clone real repositories, and authenticate with real GitHub credentials. The flaw was simple: Codex passed the target branch name into a shell command without sanitizing it, allowing characters like semicolons to terminate the intended git command. By setting the branch to \"main\" and appending a semicolon, an attacker could inject a second command that wrote the GitHub OAuth token to a file. The stolen token was then returned by Codex when the agent was asked to read the file. This flaw affected every surface where Codex is used, including the web interface, CLI, SDK, and IDE extension. Researchers confirmed that the vulnerability could be automated to compromise multiple users sharing a repository. The issue took OpenAI six weeks to fix, but the blast radius of the flaw is significant. Organizations that over-provision AI systems see 4.5 times more security incidents than those enforcing least privilege, and 70% grant AI agents higher access than a human would get. The Codex flaw illustrates the problem of permission scope: a single unsanitized string field can lead to a task holding a GitHub token with broad organizational access. Gravitee's 2026 State of AI Agent Security report found that 82% of executives believed their policies could protect against misuse or unauthorized agent actions, despite only 47.1% of AI agents being actively monitored or secured. To mitigate the risk, organizations should scope the credential to the task, not the developer, treat every free-text field as untrusted input reaching a shell, prefer short-lived, single-use credentials, and demand actual visibility into agent access. The Codex flaw has been fixed, but the pattern that made it dangerous remains widespread in enterprise AI deployments.",
  "summary": "AI coding agents don’t just suggest code anymore. Tools like OpenAI’s Codex spin up a real container, clone a real repository, and authenticate with a real GitHub credential to get the job done — which means every agent your team wires up is also a new privileged identity, holding real access, running with comparatively little […]",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}