AI SECURITY

Hacktron used Claude to chain OpenAI: forum RCE + SSO → employee Codex / internal PR.

Hacktron chained a libheif image-upload RCE on OpenAI’s Discourse forum with an OpenAI SSO token flaw, took over employee ChatGPT/Codex accounts, and opened a harmless internal PR as proof — all in under 72 hours. OpenAI paid $6,500 and fixed the identity path in ~14 hours.

Sep 18, 2026 · 4 min read

Thursday–Friday press (Wall Street Journal via TechCrunch, SecurityWeek, CyberScoop) put a frontier-lab breach research chain in front of every CISO watching AI security economics.

Primary write-up is from Hacktron AI researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini. On July 25, 2026 they chained two bugs: a heap overflow in libheif reached through HEIC/HEIF uploads on OpenAI’s Discourse-hosted forum (community.openai.com), then an OpenAI SSO misconfiguration that turned forum compromise into takeover of ChatGPT and Codex accounts for anyone who had signed in via OpenAI identity — including employees.

To prove access without reading internal source, they used an employee’s Codex (connected to OpenAI’s GitHub org) to open a harmless pull request (#1186742) in an internal monorepo, then stopped. OpenAI confirmed a fix roughly 14 hours after the Bugcrowd report, narrowed Community sign-in token permissions, revoked affected tokens/sessions, and paid a $6,500 bounty for the OpenAI-side finding (Discourse forum testing was outside bounty scope). Discourse got a separate HackerOne report and published advisory GHSA-vhm9-85gw-x335 with image-processing sandboxing.

The AI angle that made the tape: Claude Opus 4.8 struggled to weaponize the libheif bug under ASLR; within hours of Opus 5 shipping, the same problem yielded a working exploit. Hacktron frames HEIF Heist as a wider ecosystem issue (Slack, Meta, GitHub Enterprise, Rails, Next.js and peers that decode untrusted HEIF/AVIF). OpenAI told SecurityWeek the image bug lived in third-party Discourse; the account-takeover path was OpenAI’s own token overreach. OpenAI’s review: limited private-repo metadata/commit reads plus the researcher PR to a README — not a nation-state dump. Malicious victim count: Undisclosed / not applicable (responsible disclosure).

POV: this is the market event — not “AI can find bugs,” but that a three-person team compressed months of exploit craft into days and reached a frontier lab’s identity + repo surface. Patch Discourse rebuilds if you self-host; treat HEIF/AVIF decode as untrusted; audit SSO tokens that bridge community apps into ChatGPT/Codex/GitHub. Sources: Hacktron primary, TechCrunch Sep 18, SecurityWeek Sep 18. Additional repo contents, verified Slack access, and a CVE ID for the OpenAI SSO issue: Undisclosed unless OpenAI publishes them.

Underwrite sheet — sourced only: July 25 chain; libheif heap overflow via Discourse HEIC upload; OpenAI SSO / Community sign-in token overreach; employee ChatGPT/Codex takeover; PoC PR #1186742; OpenAI fix ~14h; $6,500 bounty (OpenAI-side); Discourse GHSA-vhm9-85gw-x335; Opus 4.8 struggle → Opus 5 success; HEIF Heist ecosystem warning; OpenAI statement on narrowed tokens + revoked sessions; malicious victim count Undisclosed.

Sources