OpenAI has recently addressed two critical vulnerabilities affecting its ChatGPT and Codex platforms, which could have allowed unauthorized data access and exfiltration.
Data Exfiltration Vulnerability in ChatGPT
A previously undisclosed vulnerability in ChatGPT enabled the potential exfiltration of sensitive user data without their consent. This finding was reported by Check Point, which noted that a single malicious prompt could transform a standard conversation into a covert data leak channel, exposing user messages, uploaded files, and other sensitive information.
According to Check Point, a compromised version of the AI could exploit this vulnerability to access user data without their awareness. The issue was addressed by OpenAI on February 20, 2026, following responsible disclosure. Importantly, there is currently no evidence that this vulnerability was exploited maliciously.
The vulnerability bypasses existing security measures by utilizing a hidden DNS-based communication channel, allowing data to be encoded in DNS requests. This covert transport mechanism circumvents the AI’s built-in safeguards, creating a significant security blind spot. As a result, users would not receive warnings about data leaving the conversation, nor would explicit user consent be required.
Implications for Enterprise Security
With the integration of tools like ChatGPT into enterprise environments, the implications of such vulnerabilities are profound. Organizations are urged to implement additional security layers to mitigate risks associated with prompt injections and other unexpected behaviors in AI systems. Eli Smadja from Check Point emphasized the necessity for independent visibility and layered protection, stating, “don’t assume AI tools are secure by default.” This highlights the need for a reevaluation of security architectures as AI systems become more prevalent.
Command Injection Vulnerability in OpenAI Codex
In addition to the ChatGPT vulnerability, a critical command injection flaw was discovered in OpenAI Codex, which could have been exploited to steal GitHub credentials. This vulnerability, identified by BeyondTrust, exists within the task creation HTTP request, allowing attackers to inject arbitrary commands through the GitHub branch name parameter.
This flaw, which was reported on December 16, 2025, and patched by OpenAI on February 5, 2026, could lead to the theft of a victim’s GitHub User Access Token, granting unauthorized access to shared repositories. The improper input sanitization during task execution on the cloud is the root cause of this vulnerability.
BeyondTrust researchers noted that this command injection technique could also be extended to compromise GitHub Installation Access tokens and execute commands within the code review container, further emphasizing the need for stringent security measures in AI-driven environments.
Conclusion
The vulnerabilities in both ChatGPT and Codex underscore the evolving security landscape as AI technologies become more integrated into daily operations. Organizations must remain vigilant and proactive in their security strategies to protect sensitive data from potential exploits.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








