Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

AI Coding Tools Breached Through Credential Theft, Not Code Vulnerabilities

On March 30, BeyondTrust revealed a critical vulnerability where a crafted branch name in GitHub could expose OpenAI Codex’s OAuth token in plaintext, classified as Critical P1 by OpenAI. Shortly after, Anthropic’s Claude Code source leaked on the public npm registry, with subsequent discoveries showing it ignored deny rules beyond 50 subcommands, posing serious sandbox bypass risks. Over nine months, multiple teams uncovered that exploits in Codex, Claude Code, Copilot, and Vertex AI all targeted credential theft rather than the AI models themselves. For example, Microsoft’s Copilot could be manipulated via pull request descriptions and GitHub issues to grant unauthorized root access, while Vertex AI’s default permissions allowed excessive reading of Google Cloud resources. Experts highlight that these breaches arise from inadequate identity governance and insufficient security controls around AI agent credentials, rather than flaws in AI output generation. The recommended defense is rigorous inventory and management of AI agent credentials, strict auditing of OAuth scopes, treating all user inputs as untrusted, and enforcing human session validation before AI agents access sensitive systems.

Venturebeat
Venturebeat