AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Researchers at Hacktron demonstrated a chained exploit involving an unpatched vulnerability in the libheif library used by OpenAI's community forum (Discourse) and a flaw in OpenAI's sign-in token permissions. This allowed remote code execution on the forum and subsequent takeover of OpenAI employee ChatGPT and Codex accounts, leading to access to internal code repositories. The libheif flaw was fixed upstream but not flagged as a security issue, and OpenAI quickly fixed the token permission issue after disclosure. The exploit could have allowed access to connected services like GitHub and Slack, though no evidence of such access was confirmed.
AI Analysis
Technical Summary
Hacktron researchers used AI tools to develop an exploit for a vulnerability in the libheif image decoding library, which was unpatched in OpenAI's Discourse-based community forum. This vulnerability allowed remote code execution via HEIC/HEIF image uploads. By chaining this with a separate OpenAI sign-in flaw—where tokens granted excessive API permissions—researchers took over employee ChatGPT and Codex accounts and accessed internal code repositories. The libheif flaw had been fixed upstream but was not treated as a security issue and thus missed patching cycles. OpenAI distinguished the two flaws and fixed the token permission issue within 14 hours of report, revoking affected tokens and sessions. Discourse patched the libheif vulnerability within two days and added sandboxing. The exploit demonstrated potential exposure of connected services like GitHub and Slack, though no actual Slack access was verified.
Potential Impact
The chained vulnerabilities allowed remote code execution on OpenAI's community forum and subsequent takeover of employee ChatGPT and Codex accounts. This led to access to internal code repositories, including the ability to open pull requests. Theoretically, connected services such as GitHub, Slack, and email could have been accessed through compromised accounts. OpenAI's review found limited read access to private repository metadata and commits, with no confirmed access to Slack messages. The issue exposed a significant risk of internal code and account compromise until fixed.
Mitigation Recommendations
OpenAI fixed the sign-in token permission flaw by narrowing token permissions and revoking affected tokens and sessions approximately 14 hours after disclosure. Discourse patched the libheif vulnerability within two days and implemented image-processing sandboxing as an additional defense layer. Users and employees should ensure their tokens and sessions are revoked and updated. Since fixes are available and deployed, no further immediate action is required beyond applying these patches and monitoring for unusual account activity.
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Description
Researchers at Hacktron demonstrated a chained exploit involving an unpatched vulnerability in the libheif library used by OpenAI's community forum (Discourse) and a flaw in OpenAI's sign-in token permissions. This allowed remote code execution on the forum and subsequent takeover of OpenAI employee ChatGPT and Codex accounts, leading to access to internal code repositories. The libheif flaw was fixed upstream but not flagged as a security issue, and OpenAI quickly fixed the token permission issue after disclosure. The exploit could have allowed access to connected services like GitHub and Slack, though no evidence of such access was confirmed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hacktron researchers used AI tools to develop an exploit for a vulnerability in the libheif image decoding library, which was unpatched in OpenAI's Discourse-based community forum. This vulnerability allowed remote code execution via HEIC/HEIF image uploads. By chaining this with a separate OpenAI sign-in flaw—where tokens granted excessive API permissions—researchers took over employee ChatGPT and Codex accounts and accessed internal code repositories. The libheif flaw had been fixed upstream but was not treated as a security issue and thus missed patching cycles. OpenAI distinguished the two flaws and fixed the token permission issue within 14 hours of report, revoking affected tokens and sessions. Discourse patched the libheif vulnerability within two days and added sandboxing. The exploit demonstrated potential exposure of connected services like GitHub and Slack, though no actual Slack access was verified.
Potential Impact
The chained vulnerabilities allowed remote code execution on OpenAI's community forum and subsequent takeover of employee ChatGPT and Codex accounts. This led to access to internal code repositories, including the ability to open pull requests. Theoretically, connected services such as GitHub, Slack, and email could have been accessed through compromised accounts. OpenAI's review found limited read access to private repository metadata and commits, with no confirmed access to Slack messages. The issue exposed a significant risk of internal code and account compromise until fixed.
Mitigation Recommendations
OpenAI fixed the sign-in token permission flaw by narrowing token permissions and revoking affected tokens and sessions approximately 14 hours after disclosure. Discourse patched the libheif vulnerability within two days and implemented image-processing sandboxing as an additional defense layer. Users and employees should ensure their tokens and sessions are revoked and updated. Since fixes are available and deployed, no further immediate action is required beyond applying these patches and monitoring for unusual account activity.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/","fetched":true,"fetchedAt":"2026-09-18T12:46:38.063Z","wordCount":1192}
Threat ID: 6aad32ae55bf5e2cf502cce2
Added to database: 09/18/2026, 12:46:38 UTC
Last enriched: 09/18/2026, 12:46:44 UTC
Last updated: 09/19/2026, 03:37:50 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.