ZeroHour
Vendor

Discourse

6 mentions in 7 days · 6 in 30 days · 6 total · first seen · last

Timeline

Security researchers used Claude to help them hack into OpenAInew

Three Hacktron researchers used Claude Opus to breach OpenAI employee accounts through a Discourse HEIF flaw, reaching the Monorepo within 72 hours.

A three-person team at Hacktron used Anthropic's Claude Opus 4.8 and 5 to exploit a HEIF image-processing flaw in Discourse, achieving RCE on Discourse Cloud and access to OpenAI's community forum instance within roughly a day of Claude Opus 5's July 24 launch. They reached OpenAI's GitHub Monorepo through employee accounts and proved access with a pull request from an employee's Codex account. Their HEIF Heist tooling adapted to targets including OpenAI, Slack, Meta, and GitHub Enterprise for under $3,000 in tokens, and was detected by only one target, Shopify. Discourse and OpenAI have since fixed the reported vulnerabilities, and OpenAI paid a $6,500 bounty.

The Verge · AI · 35m agoAI safety & security in the wild 2 sources

Researchers used Anthropic’s Claude to hack into OpenAI

Researchers used Claude Opus 5 to chain libheif and Discourse flaws, hijacking OpenAI employee ChatGPT and Codex accounts via bug bounty.

A three-person team at startup Hacktron AI chained a libheif memory bug (reached via crafted HEIF/HEIC uploads through Discourse's ImageMagick pipeline, never assigned a CVE) with an account-takeover flaw to access OpenAI employee ChatGPT and Codex accounts, one linked to OpenAI's GitHub organization. OpenAI paid a $6,500 bug bounty and says the issues are resolved; Discourse shipped a fix on July 27 after disclosure. Claude Opus 4.8 failed to produce a working exploit across several sessions, but Opus 5 succeeded within hours of release, underscoring how AI is collapsing the expertise needed to develop exploits.

TechCrunch · Securityupdated · 35m agofirst · 2h agoAI safety & security in the wild 2 sources

Researchers used Claude to hack OpenAI

Researchers exploited a Discourse misconfiguration on OpenAI's community forum to reach internal sign-ons and an employee ChatGPT account with GitHub code access; OpenAI fixed it.

Researchers, first reported by the Wall Street Journal, exploited a flaw in the third-party Discourse-hosted setup of OpenAI's community forum to gain access to internal sign-ons and eventually an OpenAI employee's ChatGPT account, which had access to internal code through GitHub. OpenAI thanked the researchers and said it had fixed the issues; Anthropic declined to comment and Hacktron did not immediately respond. The disclosure, which did not detail how Claude was used in the operation, coincided with Anthropic publishing data showing 26% of its R&D work was led by Claude, up from 1% in March.

Ars Technica · Securityupdated · 22m agofirst · 2h agoData breach in the wild 10 sources1

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Researchers chained a libheif RCE in Discourse with an over-privileged OpenAI forum sign-in token flaw to take over ChatGPT and Codex accounts.

Hacktron researchers used Claude Opus 4.8 and Opus 5 to weaponize an unpatched libheif decoding flaw reached through Discourse's HEIC/HEIF handling on community.openai.com, achieving remote code execution. The upstream libheif fix landed a year earlier but was never treated as a security issue, so no CVE was assigned. Chained with OpenAI-side sign-in tokens carrying excessive permissions, the researchers took over an employee's Codex-linked account and opened a pull request in an internal OpenAI GitHub repository. OpenAI narrowed token permissions and revoked sessions roughly 14 hours after the Bugcrowd report, paying a $6,500 bounty, while Discourse patched within two days and added image-processing sandboxing.

SecurityWeekupdated · 22m agofirst · 3h agoVulnerability in the wild 10 sources

Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories

Researchers used Claude Opus 5 to build a libheif exploit that compromised OpenAI's forum, hijacked employee ChatGPT/Codex accounts, and reached the internal monorepo.

On July 25, 2026, Hacktron researchers used Anthropic's Claude Opus 5, released the day before, to produce a working exploit for a libheif 1.19.7 heap-buffer overflow (CVE-2026-32882, DSA-6417-1) reached through HEIC/HEIF uploads that bypassed FastImage checks in OpenAI's Discourse forum, achieving RCE in about three hours after Claude Opus 4.8 failed under ASLR. A separate OpenAI SSO misconfiguration converted the compromised forum session into a no-interaction takeover of employees' ChatGPT and Codex accounts, from which researchers opened harmless pull request 1186742 in the private openai/openai monorepo to prove access. OpenAI fixed the issue roughly 14 hours after disclosure and awarded $6,500; Discourse published GHSA-vhm9-85gw-x335 on July 28.

Cyber Security Newsupdated · 22m agofirst · 11h agoExploit / PoC in the wild 10 sourcesCVE-2026-32882

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

Hacktron researchers chained a libheif heap overflow in Discourse with an OpenAI SSO flaw to take over employee ChatGPT/Codex accounts and access internal repositories.

On July 25, 2026, Hacktron researchers chained a heap buffer overflow in libheif 1.19.7/1.19.8 (missing Debian security backports, upstream fix never assigned a CVE), reached through Discourse image uploads processed by ImageMagick, to gain remote code execution on community.openai.com. Combined with an SSO identity misconfiguration in the 'Sign in with OpenAI' flow, they took over employees' ChatGPT/Codex accounts with connected GitHub, Slack, and email access, and proved it by opening PR #1186742 in OpenAI's internal openai/openai monorepo. They reported the issues for coordinated patching, received a $6,500 bounty from OpenAI, and Debian shipped fixed libheif packages on August 8, 2026. The team used Claude Opus 4.8 and Claude Opus 5 to locate the missing backport and autonomously develop working x86-64/ARM64 exploits.

Hacker News · securityupdated · 22m agofirst · 13h agoResearch in the wild 10 sourcesHN 334↑ · 128 comments1

Related CVEs

  • libheif is a HEIF and AVIF file format decoder and encoder.
    libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit…

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.