• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

BeyondTrust Phantom Labs finds critical OpenAI Codex vulnerability

by CXO Staff
April 6, 2026
in Future, News, Tech

BeyondTrust Phantom Labs finds a critical OpenAI Codex vulnerability enabling token theft

BeyondTrust Phantom Labs finds critical OpenAI Codex vulnerability

Researchers at BeyondTrust Phantom Labs have identified a critical command injection vulnerability in OpenAI’s Codex cloud environment that exposed GitHub OAuth tokens directly from the agent’s execution environment.

The vulnerability stemmed from improper input sanitisation in how Codex processed GitHub branch names during task execution. By injecting arbitrary commands through the GitHub branch name parameter, an attacker could execute malicious payloads inside the agent’s container and retrieve sensitive authentication tokens.

Because Codex operates with access to connected GitHub repositories, the impact extends beyond a single user. In testing, Phantom Labs demonstrated that this technique could be automated to compromise multiple users interacting with a shared repository. This issue affected multiple Codex interfaces, including ChatGPT website, Codex CLI, Codex SDK and the Codex IDE Extension.

Consequences include:

  • Token theft — Exposure of GitHub user access tokens tied to repositories, workflows, and private code
  • Organisational compromise — Potential for lateral movement across organisations using shared environments
  • Automated exploitation at scale — enabling token exfiltration across multiple users

Phantom Labs researchers also found that authentication tokens stored locally on developer machines could be leveraged to replicate the attack via backend APIs, expanding the potential blast radius.

To increase stealth and reliability, researchers developed obfuscated payload techniques using Unicode characters, allowing malicious commands to execute without being visibly detectable in the user interface.

“This research highlights a broader and growing concern: AI coding agents like Codex are not just development tools, but privileged identities operating inside live execution environments with direct access to source code, credentials, and infrastructure. This highlights a growing class of risk where automated workflows can operate outside the visibility or control of traditional security models,” commented Fletcher Davis, Director of Research for BeyondTrust Phantom Labs.

When user-controlled input is passed into these environments without strict validation, the result is not just a bug — it is a scalable attack path into enterprise systems.

Phantom Labs worked with OpenAI to responsibly disclose the issue, and all reported issues have since been remediated in coordination with OpenAI’s security team.

Find the full technical breakdown here: https://www.beyondtrust.com/blog/entry/openai-codex-command-injection-vulnerability-github-token

Tags: BeyondTrustBeyondTrust Phantom Labs finds critical OpenAI Codex vulnerabilityOpenAI Codex
ShareTweet

Related Posts

ESET launches Cloud Workload Protection and AI enhancements for ESET PROTECT customers
Future

ESET launches Cloud Workload Protection and AI enhancements for ESET PROTECT customers

April 6, 2026

ESET launched ESET Cloud Workload Protection as part of a comprehensive update for its ESET PROTECT Platform. Announced at RSAC 2026, this new module...

Kaspersky reports 2025 financial results, driving revenue to $836 million
Future

Kaspersky reports 2025 financial results, driving revenue to $836 million

April 6, 2026

Kaspersky posted positive sales results that grew by 4%* year-on-year (YoY) and approached USD 836** million in 2025. This expansion...

Discussion about this post

Latest Issue

ESET launches Cloud Workload Protection and AI enhancements for ESET PROTECT customers

ESET launches Cloud Workload Protection and AI enhancements for ESET PROTECT customers

April 6, 2026
Kaspersky reports 2025 financial results, driving revenue to $836 million

Kaspersky reports 2025 financial results, driving revenue to $836 million

April 6, 2026
Cisco appoints new VP for Saudi Arabia

Cisco appoints new VP for Saudi Arabia

April 6, 2026

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX x AI Everything
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.