conv.

All stories
SecurityQuiet 6d · day 6

Claude-Built Exploit Chained With Sign-In Flaw to Access OpenAI Code Repos

Hacktron researchers used Claude to build an exploit for a libheif vulnerability, then chained it with OpenAI's excessive sign-in token permissions to breach employee accounts.

What to know

  • Hacktron chained two distinct vulnerabilities: an unpatched libheif flaw in Discourse's image processing and overpermissioned sign-in tokens on OpenAI's side—demonstrating how multiple weak links can create critical exposure.
  • The researchers used Claude itself to build the exploit for the image-processing flaw, highlighting AI's dual use in both attack and defense.
  • OpenAI's fix arrived within 14 hours; actual exposure included limited reads of private repository metadata and one researcher-submitted pull request, with no confirmed breach of employee Slack or email.
  • The underlying libheif bug had been fixed upstream a year earlier but was never flagged as a security issue and lacked a CVE, showing gaps in vulnerability tracking.

“Hacktron says that until the issue was fixed, any user or employee who logged into the forum could have had their ChatGPT and Codex accounts taken over.”

Hacktron (via SecurityWeek) · SecurityWeek ↗

Hacktron Security research firmOpenAI Target and respondentDiscourse Third-party forum platform

Claude-Built Exploit Chained With Sign-In Flaw to Access OpenAI Code Repos
SecurityWeek

How it unfolded 2 developments, newest first · click a bar or a number to jump articles

Peak 1 piece in two hours at Sep 17, 11 PM; 2 pieces over 6 days (2 articles) Sep 17, 11 PM — 1 piece · 1 article — Newswires 1Sep 18, 1 AM — quietSep 18, 3 AM — quietSep 18, 5 AM — quietSep 18, 7 AM — 1 piece · 1 article — Newswires 1Sep 18, 9 AM — quietSep 18, 11 AM — quietSep 18, 1 PM — quietSep 18, 3 PM — quietSep 18, 5 PM — quietSep 18, 7 PM — quietSep 18, 9 PM — quietSep 18, 11 PM — quietSep 19, 1 AM — quietSep 19, 3 AM — quietSep 19, 5 AM — quietSep 19, 7 AM — quietSep 19, 9 AM — quietSep 19, 11 AM — quietSep 19, 1 PM — quietSep 19, 3 PM — quietSep 19, 5 PM — quietSep 19, 7 PM — quietSep 19, 9 PM — quietSep 19, 11 PM — quietSep 20, 1 AM — quietSep 20, 3 AM — quietSep 20, 5 AM — quietSep 20, 7 AM — quietSep 20, 9 AM — quietSep 20, 11 AM — quietSep 20, 1 PM — quietSep 20, 3 PM — quietSep 20, 5 PM — quietSep 20, 7 PM — quietSep 20, 9 PM — quietSep 20, 11 PM — quietSep 21, 1 AM — quietSep 21, 3 AM — quietSep 21, 5 AM — quietSep 21, 7 AM — quietSep 21, 9 AM — quietSep 21, 11 AM — quietSep 21, 1 PM — quietSep 21, 3 PM — quietSep 21, 5 PM — quietSep 21, 7 PM — quietSep 21, 9 PM — quietSep 21, 11 PM — quietSep 22, 1 AM — quietSep 22, 3 AM — quietSep 22, 5 AM — quietSep 22, 7 AM — quietSep 22, 9 AM — quietSep 22, 11 AM — quietSep 22, 1 PM — quietSep 22, 3 PM — quietSep 22, 5 PM — quietSep 22, 7 PM — quietSep 22, 9 PM — quietSep 22, 11 PM — quietYesterday, 1 AM — quietYesterday, 3 AM — quietYesterday, 5 AM — quietYesterday, 7 AM — quietYesterday, 9 AM — quietYesterday, 11 AM — quietYesterday, 1 PM — quietYesterday, 3 PM — quietYesterday, 5 PM — quietYesterday, 7 PM — quietYesterday, 9 PM — quietYesterday, 11 PM — quietToday, 1 AM — quietToday, 3 AM — quietToday, 5 AM — quietToday, 7 AM — quiet 1–2
Sep 18Sep 19Sep 20Sep 21Sep 22yesterdaynow · 9:44 AM ET
  1. 1

    OpenAI confirms fix and pays bug bounty; Discourse follows within two days

    OpenAI confirmed a fix for the account-takeover flaw about 14 hours after Hacktron reported it through Bugcrowd and paid a $6,500 bounty. Discourse separately patched the libheif flaw within two days and added image-processing sandboxing as defense.

    “We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.”
    — OpenAI · source
  2. 2

    Hacktron researchers demonstrate AI-assisted exploit chain accessing OpenAI internal repos

    Hacktron used Claude Opus models to build a working exploit for an unpatched libheif vulnerability in Discourse's image-processing pipeline. By chaining this with a flaw in OpenAI's community forum sign-in tokens—which carried excessive permissions—they gained access to employee ChatGPT and Codex accounts and demonstrated access to internal GitHub repositories by opening a pull request.

    1. first by SecurityWeek, 6d ago