Chained Forum RCE and SSO Flaw Let Researcher Reach OpenAI's Internal GitHub Repo
paul_cal · x · 2026-09-18
Security researcher paulcal disclosed a full exploit chain against OpenAI: HEIC/HEIF upload on the developer forum → ImageMagick decoding → libheif heap overflow for RCE, then a critical SSO flaw between the forum and ChatGPT to take over an employee's ChatGPT/Codex account, and finally access to an internal GitHub repo via PR #1186742. 'Safe forum software is an AGI-complete problem,' he quips.
Related event: HEIF Heist Image Library Flaws Hit OpenAI, Slack, Meta and GitHub(4 posts)→
More from Safety
- The real agent security weak point is over-privileged access, not faster exploits — code_star · 2026-09-18
- iPhone users report Grok notifications appearing without ever installing the app — velvetzappa · 2026-09-18
- Hijacked but well-aligned AI clusters could be more destructive than rogue AI — code_star · 2026-09-18
- Ex-OpenAI policy chief Miles Brundage quips: take AI warning shots, pass legislation — Miles_Brundage · 2026-09-18
- A Prompt to Audit Your AI Setup for the 4 Failure Modes in OpenAI's Misalignment Reports — alex_verem · 2026-09-18
- Building capable AI actors willing to cause harm is a growing x-risk, argues commenter — Borg70955376 · 2026-09-18