On July 25, 2026, Hacktron researchers demonstrated a two-vulnerability chain that compromised OpenAI employee accounts and accessed internal repositories [1]. The attack began with a heap buffer overflow in the libheif image processing library (addressed by Debian DSA-6417-1), exploited via Discourse's image upload functionality on community.openai.com [1][2]. After uploading a malicious HEIC image, Discourse's pipeline bypassed FastImage (which lacks HEIF support) and passed the file to ImageMagick's magick command, triggering the unpatched libheif parser [2][3]. This granted remote code execution with the privileges of the Discourse container [2].

The researchers then chained this with an OpenAI SSO misconfiguration to takeover employee ChatGPT and Codex accounts without additional interaction, using the latter to open a harmless pull request (#1186742) in OpenAI's internal monorepo openai/openai as proof of impact [1]. They ceased all further testing at approximately 15:30 UTC the same day to avoid accessing sensitive data [1].

Technical root cause traced to Discourse's Docker image, based on Debian 12, containing libheif version 1.19.7 missing a critical upstream security patch for a heap overflow in HEIC overlay processing [2][4]. The flaw, present for over a year without a CVE, allowed out-of-bounds memory access during image conversion when overlaying images [3]. Exploit development was accelerated by AI: initial Opus 4.8 sessions failed to bypass ASLR reliably across multiple attempts, but Opus 5 produced a working ARM64 exploit for local testing within three hours, then was prompted to port it to the x86-64 environment and jemalloc configuration used by Discourse [1][5]. We then placed Claude in an autonomous /goal loop against our own Discourse Cloud instance, proxied through rce.ee/ctf-forum to make it look like a CTF target, and when checked at 10:00 a.m.

the agent had achieved RCE on Discourse Cloud by reading /etc/hosts [1]. This reduced what would have been days of manual effort to under three hours for the core exploit, enabling rapid iteration against the live Discourse instance [1].

The SSO misconfiguration allowed a compromised forum session to leverage OpenAI's identity infrastructure at auth.openai.com, granting access to connected services including GitHub, Slack, and corporate email without re-authentication [1]. With an employee's Codex account linked to OpenAI's GitHub organization, the researchers triggered a PR in the internal openai/openai repository, demonstrating access without viewing sensitive code [1]. The entire chain from initial discovery (July 23, 05:00-06:00 UTC) to repository access (July 25, 10:00 a.m.) took less than 72 hours, coordinated via responsible disclosure to OpenAI (Bugcrowd submission at 08:00-10:00 UTC) and Discourse (HackerOne) [1]. Discourse-hosted customers had already been patched, but self-hosted instances required manual rebuild [2].

Business impact was substantial: OpenAI awarded a $6,500 bounty for the responsibly disclosed finding [1]. Beyond immediate account takeover, the breach highlighted systemic risks: any service using OpenAI SSO could be similarly exploited if compromised, and the ease of exploit development signals a shift in threat economics [1][6]. The broader HEIF Heist research project, which traced libheif dependencies across Slack, Zoom, Meta, and GitHub Enterprise, required less than $3,000 in compute tokens and two months of effort by three researchers [1]. Organizations must now account for AI-accelerated exploitation in risk models, as traditional assumptions about exploit complexity and resource requirements are obsolete [6].

Sources

  1. www.hacktron.ai/blog/hacking-openai
  2. lists.debian.org/debian-security-announce/2026/msg00328.html
  3. github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335
  4. github.com/strukturag/libheif/releases/tag/v1.23.4
  5. www.anthropic.com/news/claude-opus-5
  6. www.rand.org/pubs/research_briefs/RBA2849-1.html
  7. imagemagick.org/security-policy
  8. heif-heist.com