Security
Claude-Built Exploit Chained With Sign-In Flaw to Access OpenAI Code Repos
OpenAI confirms fix and pays bug bounty; Discourse follows within two days
1 Sep 18 · 6d ago · 1 article · 1 source · development 1 of 2
OpenAI confirmed a fix for the account-takeover flaw about 14 hours after Hacktron reported it through Bugcrowd and paid a $6,500 bounty. Discourse separately patched the libheif flaw within two days and added image-processing sandboxing as defense.
“We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”
OpenAI · rss ↗Hacktron Security research firmOpenAI Target and respondentDiscourse Third-party forum platform
The whole story articles the bright band is this development · numbered dots are the others · click one to jump
Sep 18Sep 19Sep 20Sep 21Sep 22yesterdaynow · 9:46 AM ET
Reported in the same hours no headline names this development itself — these 1 claim were published in its stretch
-
first by SecurityWeek, 6d ago
All 2 developments of Claude-Built Exploit Chained With Sign-In Flaw to Access… →
Newswires