{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreiakw4mwlevqbyoldwpwplk3chspd6bozl5zllplwoo5srddv7zyau",
"uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mj2zihkxjmj2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreiav33xmcu5jgrashozgljjv2h5xrnlxqj6ehpfsyocohqcapiwy5e"
},
"mimeType": "image/webp",
"size": 28550
},
"path": "/openai-codex-flaw-let-attackers-steal-github-access-tokens-through-command-injection/",
"publishedAt": "2026-04-08T18:13:14.000Z",
"site": "https://vpncentral.com",
"tags": [
"News",
"OpenAI Codex flaw let attackers steal GitHub access tokens through command injection",
"VPN Central"
],
"textContent": "A critical command injection flaw in OpenAI Codex let attackers steal GitHub access tokens from users and automated workflows, according to BeyondTrust Phantom Labs. The issue affected Codex across the ChatGPT website, Codex CLI, Codex SDK, and Codex IDE extension before OpenAI remediated it. The bug mattered because Codex connects directly to GitHub repositories and […]\n\nThe post OpenAI Codex flaw let attackers steal GitHub access tokens through command injection appeared first on VPN Central.",
"title": "OpenAI Codex flaw let attackers steal GitHub access tokens through command injection"
}