Tech

HacktronAI breaches OpenAI internal repositories via forum flaw

A heap overflow and SSO misconfiguration allowed security firm HacktronAI to access OpenAI’s internal codebase in under 72 hours, prompting a $6,500 bounty payment.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Hacker News · View original source
Tech
No image available
Technology

Security firm HacktronAI has disclosed that it compromised multiple OpenAI employees’ ChatGPT and Codex accounts, granting access to the company’s internal repositories. The breach was achieved by chaining a heap overflow vulnerability in the libheif library with a Single Sign-On (SSO) misconfiguration in OpenAI’s identity infrastructure. The initial entry point was OpenAI’s community forum, hosted on the Discourse platform, where uploading specific image files triggered remote code execution.

The incident, which occurred between 23 and 25 July 2026, took less than 72 hours from initial discovery to confirmed repository access. HacktronAI’s team, led by Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, identified that Discourse’s image-upload pipeline passed HEIC and HEIF files to ImageMagick for conversion. This exposed the underlying libheif parser to attacker-controlled files, allowing a heap buffer overflow in versions 1.19.7 and 1.19.8 to lead to remote code execution on the forum environment.

To demonstrate the practical impact without exposing sensitive data, the team used an employee’s Codex account to open a pull request in OpenAI’s internal monorepo. This proof of concept highlighted the broader risk, as compromised accounts could theoretically connect to various services including GitHub, Slack, and email. HacktronAI noted that the SSO misconfiguration meant that any first-party or third-party OpenAI service using the same identity flow could have been compromised, with the forum serving merely as the initial vector.

OpenAI paid a $6,500 bounty for the finding, clarifying that testing against the Discourse-hosted forum was explicitly excluded from their bug bounty program. The award specifically recognised the OpenAI-side SSO finding rather than the actions taken against the Discourse platform. Discourse responded swiftly to the report, adding image-processing sandboxing as a defence-in-depth measure and publishing advisory GHSA-vhm9-85gw-x335 with patch and rebuild guidance for self-hosted installations.

The research team utilised AI models, specifically Claude Opus 4.8 and 5.5, to develop the exploit. The newer model succeeded in creating a working exploit against ASLR-enabled environments where the previous version had struggled. This was part of a broader "HEIF Heist" research project that traced the libheif vulnerability across other platforms, including Slack, Meta, GitHub Enterprise, and various Node.js frameworks. The entire multi-month investigation cost less than $3,000 in tokens and was conducted by three researchers.

HacktronAI’s disclosure underscores a shift in the economics of exploitation, where AI is turning scarce security expertise into compute. The firm argues that security assumptions must catch up with attacker capabilities, as work that once required a well-resourced team and months of effort can now be compressed into days. They noted that while skilled human guidance remained important, the amount of work a small team could perform increased dramatically, challenging the traditional notion of security through complexity.

Continue reading

More from Tech

Read next: Cloudflare reclaims 100TB of RAM through algorithmic overhaul
Read next: Apple Watch Ultra 4 review: Battery gains and health metrics narrow the gap with Series 12
Read next: Pacing the Frontier: New report warns AI slowdown is an unsolved puzzle