Chained Forum RCE and SSO Flaw Let Researcher Reach OpenAI's Internal GitHub Repo

paul_cal · x · 2026-09-18

Security researcher paulcal disclosed a full exploit chain against OpenAI: HEIC/HEIF upload on the developer forum → ImageMagick decoding → libheif heap overflow for RCE, then a critical SSO flaw between the forum and ChatGPT to take over an employee's ChatGPT/Codex account, and finally access to an internal GitHub repo via PR #1186742. 'Safe forum software is an AGI-complete problem,' he quips.

Related event: HEIF Heist Image Library Flaws Hit OpenAI, Slack, Meta and GitHub(4 posts)→

Original post →

More from Safety

Safety channel →