Researchers Chained Two Bugs to Compromise OpenAI Internal Repos in 72 Hours
banteg · x · 2026-09-18
Security researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini published a detailed writeup of how they chained two critical vulnerabilities in July 2026 to compromise multiple OpenAI employees' ChatGPT/Codex accounts within 72 hours, gaining access to internal OpenAI repositories.
Exploit chain
- Heap buffer overflow in libheif: Debian lacked a security backport; ImageMagick uses libheif, and OpenAI's Discourse forum allowed image uploads, providing the entry point
- OpenAI SSO identity flaw: allowed takeover of employee ChatGPT/Codex accounts logging into the forum
- Connected services like GitHub, Slack, and email meant the theoretical blast radius was huge
Outcome: The team proved access by opening a PR in OpenAI's internal monorepo via the employee's Codex, immediately reported the bugs, coordinated patches with OpenAI and Discourse, and received a $6,500 bounty. LiveOverflow also published a YouTube video with technical details.
More from Safety
- Karp 称 AI 实验室推动监管实为谋求国有化以转嫁责任 — eyishazyer · 2026-09-19
- Researchers hacked OpenAI in under 72 hours; got only $6,500 as one vector 'out of scope' — random_walker · 2026-09-19
- Rep. Whitesides calls 30-day AI slowdown; Grady Booch fires back over basic security failures — PolarBearby · 2026-09-19
- OpenAI's $5M Astra Defense Beaten by 3 Guys with $5K of Opus, Argues Viral Thread — harris_edouard · 2026-09-19
- Neel Nanda: rogue agent swarms committing crimes make AI safety a present-day issue — NathanpmYoung · 2026-09-19
- Pause crowd might have it backwards: podcast debates whether halting AI is the harmful choice — thursdai_pod · 2026-09-19