
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A critical vulnerability in OpenAI's Codex coding agent allowed attackers to exploit unsanitized branch names, enabling command injection and theft of GitHub OAuth tokens. This flaw exposed developers' credentials and private repositories, risking unauthorized access and enterprise security breaches. OpenAI has since patched the vulnerability after researchers demonstrated its exploitability.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly identifies OpenAI's Codex, an AI system, as having a critical command injection flaw that could be exploited to steal authentication tokens, enabling unauthorized access and lateral movement within GitHub projects. This represents a direct security harm linked to the AI system's malfunction. Although the flaw has been patched, the incident of the vulnerability existing and being exploitable meets the criteria for an AI Incident due to realized harm or risk of harm to organizational property and security. The involvement of the AI system in the vulnerability and the resulting security implications justify classification as an AI Incident rather than a hazard or complementary information.[AI generated]