Hackers chained a heap overflow and SSO flaw to breach OpenAI internal repos in 72 hours
robleclerc · x · 2026-09-18
Security team Hacktron discloses that on July 25, 2026, it chained two critical vulnerabilities to take over multiple OpenAI employees' ChatGPT accounts within 72 hours and gain access to OpenAI's internal repositories.
- Flaw one: a heap buffer overflow in the libheif image decoder, reachable through a missing Debian security backport → ImageMagick → image uploads on the Discourse forum;
- Flaw two: an SSO identity misconfiguration on OpenAI's community forum (community.openai.com) allowing attacker-controlled login as employees into ChatGPT/Codex;
- To prove access without reading sensitive data, the researchers used an employee's Codex to open PR #1186742 in OpenAI's internal monorepo openai/openai; since Codex/ChatGPT can connect GitHub, Slack and email, the potential blast radius was huge;
- The team reported the issues immediately and worked with OpenAI and Discourse on coordinated patching; OpenAI paid a $6,500 bounty. Full timeline and technical details in the original post.
Related event: Researchers Use Claude to Breach OpenAI's Internal Codebase(23 posts)→
More from Safety
- Hackers say they took over OpenAI employee ChatGPT accounts in under 72 hours via two bugs — nptacek · 2026-09-18
- A CTF framing via /goal was all it took to bypass Claude Opus's guardrails — xeophon · 2026-09-18
- Halvar Flake: Useful AI Side Channels Face Real Information-Theoretic and Physical Limits — basedjensen · 2026-09-18
- AI safety researcher pushes back on claims that side-channel attacks make air-gapped networks insufficient — BlancheMinerva · 2026-09-18
- Geoffrey Irving: air gaps may matter someday but are laughably far from AI companies' current security — geoffreyirving · 2026-09-18
- Debate: An Exponentially Growing API-Token-Stealing Replicator Swarm May Scare More Than Weight Exfiltration — cis_female · 2026-09-18