← Back to news

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

SecurityWeek18/09/2026, 12:45••
Read full article →

Summary

AI-Generated

Key Points:

  • Hacktron researchers exploited a vulnerability in an image-processing library and a flaw in OpenAI's sign-in system to gain access to internal code repositories, including employee ChatGPT and Codex accounts.
  • The attack exploited an unpatched flaw in the libheif library via OpenAI’s community forum, allowing remote code execution and potential access to connected services like GitHub and Slack for any user who logged into the forum.
  • Immediate actions include patching the vulnerabilities, narrowing permissions on sign-in tokens, and revoking affected tokens. Organizations should ensure proper security assessments of third-party services and implement robust token management.

Technical Details: The vulnerability stemmed from an unpatched flaw in the libheif library used by ImageMagick, which was not assigned a CVE. The exploit enabled remote code execution through the Discourse platform.

MITRE ATT&CK Techniques:

  • T1203 - Exploitation for Client Execution (Initial Access)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1078 - Valid Accounts (Defense Evasion)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.