Research

Security startup says it chained a forum bug into OpenAI's internal code repository

Researchers at Hacktron AI said they used an image-processing flaw in OpenAI's community forum, combined with a single sign-on weakness, to take over employee accounts and reach a private source code repository. The work was authorized testing and was reported before being disclosed publicly.

VentureBeat reported that the chain began with HEIC and HEIF image uploads to OpenAI's Discourse-based forum, which triggered a heap buffer overflow in the libheif library and allowed code execution on that server. From there, a weakness in how single sign-on was implemented let the team reach an employee's ChatGPT and Codex accounts, one of them linked to OpenAI's GitHub organization. As proof, the researchers opened a harmless pull request in a private repository.

The team said Anthropic's Claude Opus 5 produced a working exploit within hours after an earlier model failed, and that the whole effort took under three days. Human direction was still required throughout. The researchers reported the issues in late July; OpenAI confirmed a fix the same week and paid a bounty of $6,500, and Discourse patched the underlying flaw. OpenAI has not published its own account of the episode, and Anthropic made no public comment.

Source details

Source reporting

Read the original reporting and research behind this briefing.