{
  "id": 11661419,
  "title": "A semicolon in a Codex branch name leaked its GitHub token. Scope decided the damage",
  "url": "https://urgent.news/2026/10/03/a-semicolon-in-a-codex-branch-name-leaked-its-github-token-scope",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T10:24:21.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/leobaniak/a-semicolon-in-a-codex-branch-name-leaked-its-github-token-scope-decided-the-damage-32o9"
  },
  "original_language": "en",
  "account": "A seemingly innocuous semicolon in a branch name of a GitHub repository has proven to be a critical vulnerability, according to a report from DevOps.com. The flaw, disclosed by BeyondTrust's Phantom Labs in March, allows malicious actors to extract a GitHub OAuth token from OpenAI's Codex. OpenAI has since patched the issue, but the potential impact remains significant. The vulnerability arises when Codex generates a task container and passes the branch name into a shell command without sanitizing it first. This oversight allows malicious code to be injected and executed. Bash interprets characters such as semicolons, &&, |, $(), and backticks as shell syntax rather than part of the branch name. In a proof of concept, researchers demonstrated how the token could be extracted by appending a second command to the git command that writes the output of git remote get-url origin to a file. The bug can affect every surface of Codex, including the web interface, CLI, SDK, and IDE extension. According to a survey by Teleport, organizations that over-provision AI systems experience 4.5 times more security incidents than those enforcing least privilege. The report also found that 70% of organizations give AI agents more access than a human doing the same task, and 67% still use static credentials for AI systems. The article recommends hardening the input path by stopping the building of shell strings and using allowlists, quoting values, and treating input as hostile. Moving the token out of the remote URL and into a credential helper or git config header also reduces the risk. Limiting the scope and lifetime of the token, requesting visibility into the agent's credential capabilities, and using short-lived, single-use credentials are additional measures suggested to mitigate the impact of this vulnerability.",
  "summary": "A branch name with a semicolon in it was enough to pull a GitHub OAuth token out of OpenAI's Codex, according to a DevOps.com write-up of a critical flaw that BeyondTrust's Phantom Labs disclosed in March. OpenAI has fixed it. For teams wiring agents into their delivery pipelines, the bug matters less than the token. Its scope decided how far a single injected command could reach. The mechanism…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}