HEIF image exploit chains into OpenAI internal GitHub via Discourse forum bug

jedisct1 · x · 2026-09-18

Hacktron researchers disclosed a chained attack on OpenAI: the community forum runs Discourse, which shipped an outdated libheif image decoder with a bug fixed upstream but never labeled as a security fix. A crafted HEIF upload yielded remote code execution on community.openai.com.

A second flaw in OpenAI's single sign-on ("log in with OpenAI") turned the forum foothold into access to actual ChatGPT and Codex accounts, ending with a pull request inside OpenAI's internal GitHub.

Key lesson: because the libheif fix wasn't tagged as security-critical, many sites never patched — off-the-shelf forum software like Discourse is a wide attack surface.

Related event: HEIF Heist: Image Decoder Flaws Let Hackers Breach OpenAI, Meta and More(6 posts)→

Original post →

More from Safety

Safety channel →