{"id":5200,"date":"2026-09-30T20:26:13","date_gmt":"2026-09-30T20:26:13","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/30\/a-semicolon-in-a-branch-name-was-all-it-took-to-steal-an-ai-agents-github-token\/"},"modified":"2026-09-30T20:26:13","modified_gmt":"2026-09-30T20:26:13","slug":"a-semicolon-in-a-branch-name-was-all-it-took-to-steal-an-ai-agents-github-token","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/30\/a-semicolon-in-a-branch-name-was-all-it-took-to-steal-an-ai-agents-github-token\/","title":{"rendered":"A Semicolon in a Branch Name Was All It Took to Steal an AI Agent\u2019s GitHub Token"},"content":{"rendered":"<div><img data-opt-id=246651488  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/Githubtoken-1-e1790796039460.jpeg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=1711152798  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/09\/Githubtoken-1-150x150.jpeg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p data-pm-slice=\"1 1 []\">AI coding agents don\u2019t just suggest code anymore. Tools like OpenAI\u2019s Codex spin up a real container, clone a real repository, and authenticate with a real GitHub credential to get the job done \u2014 which means every agent your team wires up is also a new privileged identity, holding real access, running with comparatively little of the scrutiny a human with that same access would get.<\/p>\n<h3><strong>A Branch Name Was the Whole Attack<\/strong><\/h3>\n<p>In March, BeyondTrust\u2019s Phantom Labs disclosed a critical command injection vulnerability in Codex. The flaw was almost absurdly simple: when Codex creates a task container, it passes the target branch name into a shell command without sanitizing it first. Characters like <em>; &amp;&amp; | $()<\/em> and backticks get interpreted literally by Bash.<\/p>\n<p>The proof-of-concept needed nothing more exotic than that. Set the branch to <em>main<\/em>, append a semicolon to terminate the intended git command, then inject a second command that writes the output of <em>git remote get-url origin<\/em> \u2014 which contains the GitHub OAuth token in cleartext \u2014 to a file. Then simply ask the agent, in the prompt, to read that file back. Codex did exactly what it was built to do: it read the file and returned its contents. The stolen token came back inside the agent\u2019s own task output.<\/p>\n<p>The flaw hit every surface Codex ships \u2014 the ChatGPT web interface, the CLI, the SDK, the IDE extension \u2014 and researchers confirmed it could be automated to compromise multiple users sharing a repository, not just one. Fixing it took OpenAI roughly six weeks of iterative hardening before the issue was classified Critical and cleared for public disclosure.<\/p>\n<h3><strong>The Bug Isn\u2019t the Real Problem. The Blast Radius Is.<\/strong><\/h3>\n<p>A sanitization bug gets patched. What doesn\u2019t automatically get fixed alongside it is how much a compromised agent credential is actually worth \u2014 and on that question, Teleport\u2019s 2026 State of AI in Enterprise Infrastructure Security report, based on interviews with 205 CISOs and security architects, has numbers worth sitting with: organizations that over-provision AI systems see <strong>4.5 times<\/strong> more security incidents than those enforcing least privilege. 70% admit they grant AI agents higher access than a human doing the identical task would get. 67% still rely on static credentials for AI systems.<\/p>\n<p>The Codex flaw illustrates the related problem of permission scope: a single unsanitized string field fed a container holding a GitHub token with access extending beyond the immediate task. The vulnerability made the theft possible. The permission scope decided what the theft was actually worth. Stealing a token that can only touch one branch of one repo is an inconvenience. Stealing one with broad organizational access can become an organization-wide GitHub compromise that happens to have started inside a coding assistant.<\/p>\n<p>Gravitee\u2019s 2026 State of AI Agent Security report found a similar confidence gap: 82% of executive respondents said they were confident their policies could protect against misuse or unauthorized agent actions, even though, on average, only 47.1% of an organization\u2019s AI agents were actively monitored or secured. That gap is exactly where an unsanitized branch name turns into a production incident nobody saw coming.<\/p>\n<h3><strong>What to Actually Check Before You Ship an Agent<\/strong><\/h3>\n<p>\u25cf <strong>Scope the credential to the task, not to the developer.<\/strong> If an agent only needs to open a pull request on one repository, it has no business holding a token with the same reach as the human who configured it.<\/p>\n<p>\u25cf <strong>Treat every free-text field an agent\u2019s task flow accepts as untrusted input reaching a shell.<\/strong> Branch names, file paths, commit messages, ticket titles \u2014 any of them can become <a href=\"https:\/\/hackita.it\/articoli\/command-injection\/\">command injection<\/a> the moment they\u2019re passed unsanitized into a subprocess, exactly as happened here.<\/p>\n<p>\u25cf <strong>Prefer short-lived, single-use credentials over static tokens.<\/strong> A token scoped to one task and expiring when it\u2019s done limits a successful theft to that one task, no matter how the theft happened.<\/p>\n<p>\u25cf <strong>Ask for actual visibility into agent access, not a policy document about it.<\/strong> If your team can\u2019t answer \u201cwhat could this agent\u2019s credential actually do right now\u201d with a specific list of repos and scopes, the confidence gap between policy and actual agent visibility should concern you.<\/p>\n<h3><strong>The Bottom Line<\/strong><\/h3>\n<p>The Codex flaw is fixed. The pattern that made it dangerous \u2014 an agent holding more access than its task requires \u2014 remains widespread in enterprise AI deployments. Static credentials can make that problem worse by allowing compromised access to persist beyond a single task. The sanitization bug was the easy part to find. The permission scope is the part worth checking before the next one is.<\/p>\n<p><a href=\"https:\/\/devops.com\/a-semicolon-in-a-branch-name-was-all-it-took-to-steal-an-ai-agents-github-token\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>AI coding agents don\u2019t just suggest code anymore. Tools like OpenAI\u2019s Codex spin up a real container, clone a real [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5201,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5200","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5200","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5200"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5200\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5201"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5200"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}