Skip to main content

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

0
High
Vulnerability
Published: 09/18/2026 (09/18/2026, 12:45:24 UTC)
Source: SecurityWeek

Description

Researchers at Hacktron demonstrated a chained exploit involving an unpatched vulnerability in the libheif library used by OpenAI's community forum (Discourse) and a flaw in OpenAI's sign-in token permissions. This allowed remote code execution on the forum and subsequent takeover of OpenAI employee ChatGPT and Codex accounts, leading to access to internal code repositories. The libheif flaw was fixed upstream but not flagged as a security issue, and OpenAI quickly fixed the token permission issue after disclosure. The exploit could have allowed access to connected services like GitHub and Slack, though no evidence of such access was confirmed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 12:46:44 UTC

Technical Analysis

Hacktron researchers used AI tools to develop an exploit for a vulnerability in the libheif image decoding library, which was unpatched in OpenAI's Discourse-based community forum. This vulnerability allowed remote code execution via HEIC/HEIF image uploads. By chaining this with a separate OpenAI sign-in flaw—where tokens granted excessive API permissions—researchers took over employee ChatGPT and Codex accounts and accessed internal code repositories. The libheif flaw had been fixed upstream but was not treated as a security issue and thus missed patching cycles. OpenAI distinguished the two flaws and fixed the token permission issue within 14 hours of report, revoking affected tokens and sessions. Discourse patched the libheif vulnerability within two days and added sandboxing. The exploit demonstrated potential exposure of connected services like GitHub and Slack, though no actual Slack access was verified.

Potential Impact

The chained vulnerabilities allowed remote code execution on OpenAI's community forum and subsequent takeover of employee ChatGPT and Codex accounts. This led to access to internal code repositories, including the ability to open pull requests. Theoretically, connected services such as GitHub, Slack, and email could have been accessed through compromised accounts. OpenAI's review found limited read access to private repository metadata and commits, with no confirmed access to Slack messages. The issue exposed a significant risk of internal code and account compromise until fixed.

Mitigation Recommendations

OpenAI fixed the sign-in token permission flaw by narrowing token permissions and revoking affected tokens and sessions approximately 14 hours after disclosure. Discourse patched the libheif vulnerability within two days and implemented image-processing sandboxing as an additional defense layer. Users and employees should ensure their tokens and sessions are revoked and updated. Since fixes are available and deployed, no further immediate action is required beyond applying these patches and monitoring for unusual account activity.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/","fetched":true,"fetchedAt":"2026-09-18T12:46:38.063Z","wordCount":1192}

Threat ID: 6aad32ae55bf5e2cf502cce2

Added to database: 09/18/2026, 12:46:38 UTC

Last enriched: 09/18/2026, 12:46:44 UTC

Last updated: 09/19/2026, 03:37:50 UTC

Views: 33

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses