Critical Vulnerability in OpenAI Codex Could Allow GitHub Token Theft via Unicode Injection
185/69 Wednesday, April 1, 2026 Researchers from BeyondTrust Phantom Labs have disclosed a critical vulnerability in OpenAI Codex that could be exploited to steal GitHub OAuth tokens. The flaw is a command injection vulnerability caused by insufficient input sanitization, allowing attackers to embed malicious commands within GitHub branch names. Notably, the attack leverages special Unicode […]
