08 Apr BeyondTrust phantom labs finds critical OpenAI Codex vulnerability enabling token theft
[info_box point1="Researchers at BeyondTrust Phantom Labs have identified a critical command injection vulnerability in OpenAI’s Codex" point2="The vulnerability stemmed from improper input sanitisation in Codex's processing of GitHub branch names" point3="An attacker could execute malicious payloads inside the agent’s container and retrieve sensitive authentication tokens"] Researchers...