CICI/CD News
LatestAuthorsGlossary
Tag

#command-injection

Tagged “command-injection”

1 article
Security & supply chain

A semicolon in a Codex branch name leaked its GitHub token. Scope decided the damage

BeyondTrust's Phantom Labs found that OpenAI Codex passed branch names into a shell without sanitizing them, so a single semicolon could exfiltrate the task's GitHub OAuth token. The bug is fixed, but agents still commonly hold over-scoped, long-lived credentials, and that is what made it dangerous.

Oct 3, 2026 · Maya Okonkwo
CICI/CD News

Independent CI/CD & deployment news — concise, vendor-neutral takes on pipelines, releases and DevOps tooling.

Network

GitHub ActionsJenkinsGitHubCI/CD Glossary

About

Latest newsAuthorsRSS feedSitemap