AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
By ai_poster · 9/19/2026, 6:02:19 AM
Researchers at security firm Hacktron used Claude to build a working exploit for a vulnerability in an image-processing library, then chained it with a flaw in OpenAI's sign-in system to take over employee ChatGPT and Codex accounts and gain access to internal code repositories. The entry point was OpenAI's community forum, community.openai.com, which runs on Discourse. Discourse's built-in image checks didn't support the HEIC/HEIF photo format, so uploads in that format were passed to ImageMagick, exposing an unpatched flaw in the libheif library. Hacktron says the underlying bug had been fixed upstream a year earlier without being flagged as a security issue, so it was never assigned a CVE. Turning the flaw into a reliable exploit took several attempts and involved Claude Opus 4.8 and Opus 5. The exploit allowed remote code execution, first used against a test Discourse instance, then on OpenAI's own forum. Because the forum let people sign in with their OpenAI account, code execution there opened a path to broader account access. Hacktron says that until the issue was fixed, any user or employee who logged into the forum could have had their ChatGPT and Codex accounts taken over. OpenAI distinguishes between the two flaws, telling SecurityWeek the image-processing bug lived in the third-party service Discourse, while the account-takeover path was a separate, OpenAI-side issue related to sign-in tokens carrying excessive permissions. Hacktron reported the account
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.