‹ Back to Home

OpenAI Just Patched Two Serious Security Holes in ChatGPT and Codex — One Could Have Leaked Your Entire Conversation History

Security researchers discovered two separate vulnerabilities in OpenAI's products — one that could silently steal your ChatGPT conversations through a hidden DNS channel, and another that let attackers steal GitHub access tokens via OpenAI's Codex coding agent. Both have been patched. Here's what happened and what it means for you.

Keerthika 7 min read 737
Follow on Google
Updated 5 months ago
Security OpenAI Just Patched Two Serious Security Holes in ChatGPT and Codex — One Could Have Leaked Your Entire Conversation History 7 min left Follow on Google
OpenAI Just Patched Two Serious Security Holes in ChatGPT and Codex — One Could Have Leaked Your Entire Conversation History

TamilTech AI summary

OpenAI recently fixed two serious security vulnerabilities—one in ChatGPT’s code‑execution sandbox that could leak conversation data via DNS queries, and another in Codex that could steal GitHub OAuth tokens through a command‑injection flaw in branch‑name handling. Both bugs were responsibly disclosed by independent researchers, patched before any known exploitation, showing the disclosure process worked but also highlighting how AI platforms have broader attack surfaces than traditional software. The ChatGPT flaw mainly threatened users who upload sensitive files or share personal/business data, as a malicious prompt could silently exfiltrate that information; the Codex flaw put developers at risk of losing GitHub tokens that could grant access to private repos, API keys, and CI/CD pipelines. Since the patches are server‑side, users don’t need to take any immediate action, but it’s wise to be cautious about what you share in ChatGPT and to review or rotate GitHub tokens used with Codex, applying the principle of least privilege. For India’s fast‑growing developer community, where many rely on Codex for private‑repo work, this serves as a reminder to tighten token scopes and stay vigilant as AI agents become more deeply integrated into coding workflows.

  • ChatGPT had a hidden DNS exfiltration channel that could silently leak conversation data and uploaded files — patched by OpenAI, no confirmed real-world exploitation
  • Codex GitHub token vulnerability allowed OAuth token theft via malicious branch name injection — affected web, CLI, SDK, and IDE integrations
  • Both fixed before exploitation; Indian developers using Codex with enterprise GitHub should audit token scopes and rotate credentials as precaution

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

Two bugs, one company — and your data was potentially at risk

OpenAI has quietly patched two significant security vulnerabilities discovered by independent security researchers — one in ChatGPT and one in its Codex AI coding agent. Neither appears to have been exploited in the wild before the fixes landed, but the technical details of both bugs are worth understanding because they reveal something important about how AI platforms handle security at their core.

Both vulnerabilities were responsibly disclosed — meaning the researchers who found them reported them to OpenAI privately before going public, giving the company time to fix the issues before attackers could exploit them. That's the right process, and OpenAI responded quickly. But the fact that these bugs existed at all is a reminder that AI systems have attack surfaces that are fundamentally different from traditional software.

Bug #1: The ChatGPT data exfiltration flaw

This one is the more alarming of the two for regular ChatGPT users. Security researchers discovered a vulnerability in ChatGPT's code execution environment — the sandboxed system that runs Python code when you ask ChatGPT to write and execute scripts.

Here's how the attack worked. ChatGPT's code execution environment has protections that normally prevent it from making direct outbound internet connections or sending your data anywhere without you knowing. These protections exist specifically to prevent the kind of data theft that this bug enabled. But researchers found a hidden channel that bypassed these controls: DNS queries.

DNS (Domain Name System) is how your device translates website names like "google.com" into the IP addresses computers actually use to connect. DNS queries are so fundamental to how the internet works that they're often less tightly restricted than regular outbound HTTP connections. The vulnerability exploited this gap.

An attacker could craft a malicious prompt — a carefully worded message to ChatGPT — that, when processed, would cause the code execution environment to encode sensitive information from your conversation (uploaded files, shared data, conversation history) into tiny fragments and transmit them outward through DNS queries to attacker-controlled servers. The entire process could happen silently, without any warning to the user. No notification, no confirmation dialog, no indicator that data was leaving the session.

For a typical person using ChatGPT to ask general questions, this vulnerability was largely theoretical — there's no particularly sensitive data to steal from a conversation about recipe ideas. But ChatGPT Plus users frequently upload documents, share business data, paste code with API keys, provide financial information, or discuss sensitive personal topics. For those users, a targeted malicious prompt could have been used to silently exfiltrate the contents of an entire session.

OpenAI has patched this by tightening the DNS access controls within the code execution sandbox. The fix blocks the DNS-based exfiltration channel that researchers demonstrated.

Bug #2: The Codex GitHub token theft vulnerability

Codex is OpenAI's AI coding agent — a tool designed to help developers write, review, and execute code tasks autonomously. It runs in cloud containers and, crucially, authenticates with GitHub using short-lived OAuth tokens to access repositories and execute tasks on behalf of the developer.

Researchers at BeyondTrust Phantom Labs discovered a command injection vulnerability in how Codex handles GitHub repository cloning. When Codex clones a repository, it uses the repository's branch name as part of the shell command that executes the clone operation. The vulnerability was that Codex didn't properly sanitize this input.

An attacker who could get a developer to interact with a maliciously crafted repository — one with a specially constructed branch name — could inject arbitrary shell commands into the Codex execution environment during the cloning process. Those injected commands would run with the same permissions as Codex itself, which means they had access to the GitHub OAuth token being used for authentication.

Stealing that OAuth token is a significant win for an attacker. GitHub OAuth tokens can grant access to private repositories, read source code, push malicious commits, access CI/CD pipelines, and potentially move laterally into other connected services within an enterprise GitHub organisation. For a developer working on a company codebase, a stolen GitHub token could mean an attacker gaining access to proprietary code, infrastructure configurations, API keys stored in private repos, and deployment credentials.

The vulnerability also extended beyond the web interface — it affected Codex's command-line interface, SDK, and IDE integrations, meaning the attack surface was broad across the different ways developers use Codex in their workflows.

OpenAI's fix addressed this with improved input validation on branch names, stronger shell escaping protections that prevent injected characters from being interpreted as commands, and tighter controls around token exposure within the container environment.

Why this matters for Indian developers especially

India has one of the fastest-growing developer communities in the world. GitHub's annual report consistently ranks India among the top countries for new developer accounts and open-source contributions. A large and growing number of Indian developers working at startups, IT services companies, and enterprise organisations are already using AI coding tools including Codex as part of their daily workflows.

The Codex vulnerability is particularly relevant to this audience. Many Indian IT services companies host client code on private GitHub repositories, manage infrastructure-as-code in private repos, and store environment configurations that include credentials for cloud services. A compromised GitHub token in an enterprise GitHub organisation doesn't just expose one repository — it can cascade across everything that token has access to.

For freelance developers and startup teams, which are common in India's tech ecosystem, the same risk applies at a smaller scale. Code that gets monetised through side projects, client work, or startup products is often in private GitHub repos with configurations that include database credentials, payment gateway keys, or cloud API tokens.

What should you do right now?

For the ChatGPT data exfiltration vulnerability: OpenAI has patched this server-side, meaning you don't need to take any action. The fix is already live. However, it's a good reminder to be thoughtful about what you share in ChatGPT sessions — especially uploaded documents that contain sensitive personal or business information.

For the Codex GitHub token vulnerability: If you use Codex in your development workflow, the patches are deployed. Again, no action required on your end. But this is a good moment to review your GitHub token scopes — make sure the tokens you're using for development tools have the minimum necessary permissions rather than broad repository access. GitHub allows you to create fine-grained personal access tokens with specific repository and permission restrictions. If your Codex integration is using a broad-scope token, consider creating a restricted one with only the access it actually needs.

General hygiene: rotate any GitHub tokens that you've been using with AI tools over the last few months, particularly if you can't verify the exact permissions and exposure of those tokens. It takes five minutes and removes any residual risk from periods before the patches.

TamilTech's take

The responsible disclosure process worked here — researchers found the bugs, told OpenAI privately, OpenAI fixed them before they were exploited. That's the system functioning correctly. What's worth reflecting on is the nature of these attack surfaces. AI systems that execute code, make network requests, and authenticate with external services on your behalf have fundamentally broader attack surfaces than a regular app. The same capabilities that make ChatGPT's code execution useful (it can access the network to fetch data) are the ones that created the exfiltration channel. The same capabilities that make Codex useful (it authenticates with GitHub to do things automatically) are what made the token theft possible. As AI agents become more capable and more deeply integrated into development workflows, these security trade-offs are going to matter more and more.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,344 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications