Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories
Researchers used Claude Opus 5 to build a libheif exploit that compromised OpenAI's forum, hijacked employee ChatGPT/Codex accounts, and reached the internal monorepo.
On July 25, 2026, Hacktron researchers used Anthropic's Claude Opus 5, released the day before, to produce a working exploit for a libheif 1.19.7 heap-buffer overflow (CVE-2026-32882, DSA-6417-1) reached through HEIC/HEIF uploads that bypassed FastImage checks in OpenAI's Discourse forum, achieving RCE in about three hours after Claude Opus 4.8 failed under ASLR. A separate OpenAI SSO misconfiguration converted the compromised forum session into a no-interaction takeover of employees' ChatGPT and Codex accounts, from which researchers opened harmless pull request 1186742 in the private openai/openai monorepo to prove access. OpenAI fixed the issue roughly 14 hours after disclosure and awarded $6,500; Discourse published GHSA-vhm9-85gw-x335 on July 28.