Tools AI Risk Radar ai-incident-0071
Incident record
OpenAI patches ChatGPT data-exfiltration flaw and Codex token vulnerability
- Severity
- High
- Status
- Patched
- Type
- Agent Hijack
- Target
- OpenAI ChatGPT
- Actor
- researcher
What happened
Check Point and BeyondTrust disclosed separate flaws in OpenAI's products: one turned DNS lookups from ChatGPT's code-execution sandbox into a covert channel that leaked conversation text and uploaded files, while a second let a crafted GitHub branch name inject shell commands into Codex's cloud container, stealing the victim's GitHub user access token, the same token Codex authenticates with, and running attacker code beside the developer's own. OpenAI patched both issues, ChatGPT on 20 February 2026 and Codex in stages from 23 December 2025 to 30 January 2026. No in-the-wild abuse was reported.
The Codex vector worked because GitHub bars spaces in branch names but not ${IFS}, so shell metacharacters survived the naming rules and ran inside the task container. It reached the ChatGPT website, the Codex CLI, the Codex SDK and the Codex IDE extension. Neither flaw carries a CVE.
Sources
- Check Point Research: ChatGPT data leakage through a hidden outbound channel in the code execution runtime (30 March 2026)research.checkpoint.com/2026/chatgpt-data-leakage-via-a-hidd…
- BeyondTrust Phantom Labs: command injection in OpenAI Codex and theft of the GitHub token (30 March 2026)www.beyondtrust.com/blog/entry/openai-codex-command-injectio…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026