Two bugs, one company — and your data was potentially at risk
OpenAI has quietly patched two significant security vulnerabilities discovered by independent security researchers — one in ChatGPT and one in its Codex AI coding agent. Neither appears to have been exploited in the wild before the fixes landed, but the technical details of both bugs are worth understanding because they reveal something important about how AI platforms handle security at their core.
Both vulnerabilities were responsibly disclosed — meaning the researchers who found them reported them to OpenAI privately before going public, giving the company time to fix the issues before attackers could exploit them. That's the right process, and OpenAI responded quickly. But the fact that these bugs existed at all is a reminder that AI systems have attack surfaces that are fundamentally different from traditional software.
Bug #1: The ChatGPT data exfiltration flaw
This one is the more alarming of the two for regular ChatGPT users. Security researchers discovered a vulnerability in ChatGPT's code execution environment — the sandboxed system that runs Python code when you ask ChatGPT to write and execute scripts.
Here's how the attack worked. ChatGPT's code execution environment has protections that normally prevent it from making direct outbound internet connections or sending your data anywhere without you knowing. These protections exist specifically to prevent the kind of data theft that this bug enabled. But researchers found a hidden channel that bypassed these controls: DNS queries.
DNS (Domain Name System) is how your device translates website names like "google.com" into the IP addresses computers actually use to connect. DNS queries are so fundamental to how the internet works that they're often less tightly restricted than regular outbound HTTP connections. The vulnerability exploited this gap.
An attacker could craft a malicious prompt — a carefully worded message to ChatGPT — that, when processed, would cause the code execution environment to encode sensitive information from your conversation (uploaded files, shared data, conversation history) into tiny fragments and transmit them outward through DNS queries to attacker-controlled servers. The entire process could happen silently, without any warning to the user. No notification, no confirmation dialog, no indicator that data was leaving the session.
For a typical person using ChatGPT to ask general questions, this vulnerability was largely theoretical — there's no particularly sensitive data to steal from a conversation about recipe ideas. But ChatGPT Plus users frequently upload documents, share business data, paste code with API keys, provide financial information, or discuss sensitive personal topics. For those users, a targeted malicious prompt could have been used to silently exfiltrate the contents of an entire session.
OpenAI has patched this by tightening the DNS access controls within the code execution sandbox. The fix blocks the DNS-based exfiltration channel that researchers demonstrated.
Bug #2: The Codex GitHub token theft vulnerability
Codex is OpenAI's AI coding agent — a tool designed to help developers write, review, and execute code tasks autonomously. It runs in cloud containers and, crucially, authenticates with GitHub using short-lived OAuth tokens to access repositories and execute tasks on behalf of the developer.
Researchers at BeyondTrust Phantom Labs discovered a command injection vulnerability in how Codex handles GitHub repository cloning. When Codex clones a repository, it uses the repository's branch name as part of the shell command that executes the clone operation. The vulnerability was that Codex didn't properly sanitize this input.
An attacker who could get a developer to interact with a maliciously crafted repository — one with a specially constructed branch name — could inject arbitrary shell commands into the Codex execution environment during the cloning process. Those injected commands would run with the same permissions as Codex itself, which means they had access to the GitHub OAuth token being used for authentication.
Stealing that OAuth token is a significant win for an attacker. GitHub OAuth tokens can grant access to private repositories, read source code, push malicious commits, access CI/CD pipelines, and potentially move laterally into other connected services within an enterprise GitHub organisation. For a developer working on a company codebase, a stolen GitHub token could mean an attacker gaining access to proprietary code, infrastructure configurations, API keys stored in private repos, and deployment credentials.
The vulnerability also extended beyond the web interface — it affected Codex's command-line interface, SDK, and IDE integrations, meaning the attack surface was broad across the different ways developers use Codex in their workflows.
OpenAI's fix addressed this with improved input validation on branch names, stronger shell escaping protections that prevent injected characters from being interpreted as commands, and tighter controls around token exposure within the container environment.
Why this matters for Indian developers especially
India has one of the fastest-growing developer communities in the world. GitHub's annual report consistently ranks India among the top countries for new developer accounts and open-source contributions. A large and growing number of Indian developers working at startups, IT services companies, and enterprise organisations are already using AI coding tools including Codex as part of their daily workflows.
The Codex vulnerability is particularly relevant to this audience. Many Indian IT services companies host client code on private GitHub repositories, manage infrastructure-as-code in private repos, and store environment configurations that include credentials for cloud services. A compromised GitHub token in an enterprise GitHub organisation doesn't just expose one repository — it can cascade across everything that token has access to.
For freelance developers and startup teams, which are common in India's tech ecosystem, the same risk applies at a smaller scale. Code that gets monetised through side projects, client work, or startup products is often in private GitHub repos with configurations that include database credentials, payment gateway keys, or cloud API tokens.
What should you do right now?
For the ChatGPT data exfiltration vulnerability: OpenAI has patched this server-side, meaning you don't need to take any action. The fix is already live. However, it's a good reminder to be thoughtful about what you share in ChatGPT sessions — especially uploaded documents that contain sensitive personal or business information.
For the Codex GitHub token vulnerability: If you use Codex in your development workflow, the patches are deployed. Again, no action required on your end. But this is a good moment to review your GitHub token scopes — make sure the tokens you're using for development tools have the minimum necessary permissions rather than broad repository access. GitHub allows you to create fine-grained personal access tokens with specific repository and permission restrictions. If your Codex integration is using a broad-scope token, consider creating a restricted one with only the access it actually needs.
General hygiene: rotate any GitHub tokens that you've been using with AI tools over the last few months, particularly if you can't verify the exact permissions and exposure of those tokens. It takes five minutes and removes any residual risk from periods before the patches.
TamilTech's take
The responsible disclosure process worked here — researchers found the bugs, told OpenAI privately, OpenAI fixed them before they were exploited. That's the system functioning correctly. What's worth reflecting on is the nature of these attack surfaces. AI systems that execute code, make network requests, and authenticate with external services on your behalf have fundamentally broader attack surfaces than a regular app. The same capabilities that make ChatGPT's code execution useful (it can access the network to fetch data) are the ones that created the exfiltration channel. The same capabilities that make Codex useful (it authenticates with GitHub to do things automatically) are what made the token theft possible. As AI agents become more capable and more deeply integrated into development workflows, these security trade-offs are going to matter more and more.




Comments (0)
Be the first to comment!