Threat reportVulnerabilityTL-2026-2558

AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)

highPATCHED

AI-Driven Exploit Chain Against OpenAI Community Forum via (TL-2026-2558), also tracked as HEIF Heist, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-09-18 and last reviewed 2026-09-27. It is attributed to Hacktron AI with high confidence, affects strukturag libheif, references 1 CVE (CVE-2026-32882), maps to 23 MITRE ATT&CK / ATLAS techniques (AML.T0054, T1016, T1059), and is covered by 9 detection rules and 28 indicators of compromise.

CVSS
8.8/10High
CVEs
1Referenced vulnerabilities
Techniques
23MITRE ATT&CK / ATLAS
Actors
1Hacktron AI
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-2558

Threat ID
TL-2026-2558
Also known as
HEIF Heist, Hacking OpenAI
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution
Hacktron AI
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
technology, software development, artificial intelligence
Target regions
Global
Detection rules
9
Indicators of compromise
28
Updates
2026-09-27 · 2 updates · revalidated 2× · latest source

Malware and tooling in AI-Driven Exploit Chain Against OpenAI Community Forum via

Malware and tooling: Bugcrowd, ChatGPT, Claude Opus 4.8, Claude Opus 5, HackerOne, OpenAI Codex

How AI-Driven Exploit Chain Against OpenAI Community Forum via works

Hacktron AI researchers used Claude Opus 5 to autonomously develop a heap-overflow exploit for CVE-2026-32882, a libheif overlay-compositing OOB read in Debian 12's Discourse Docker image, achieving RCE on OpenAI's community.openai.com forum via a malformed HEIC upload. A subsequent OpenAI SSO misconfiguration let the compromised forum session hijack a connected employee's ChatGPT/Codex accounts and open a pull request in OpenAI's private GitHub monorepo.

In July 2026, researchers at Hacktron AI (Harsh Jaiswal, Mohan Pedhapati, Rahul Maini) targeted the Discourse-hosted community.openai.com support forum as part of a broader campaign the firm calls 'HEIF Heist,' which probed HEIC/HEIF image-decoding pipelines across Slack, Meta, GitHub Enterprise, Ruby on Rails, Next.js, Astro, Gatsby, and Zoom. Discourse's Docker image (based on Debian 12) shipped libheif 1.19.7, which was missing an upstream heap-overflow backport, and Discourse's upload pipeline invoked ImageMagick's `magick` utility to convert HEIC/HEIF images -- a format FastImage could not validate -- routing untrusted attacker-controlled files directly into the vulnerable libheif decoder.

The root technical flaw the researchers weaponized is tracked as CVE-2026-32882: a heap buffer over-read in `HeifPixelImage::overlay()` (libheif/pixelimage.cc), which indexes an overlay image's alpha plane using the color-channel stride instead of the correct alpha stride when the two channels have mismatched bit depths, reading up to 3,123 bytes past the end of the alpha buffer for a 100x50 image mixing 10-bit color and 8-bit alpha. NVD rates the underlying library bug 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H, CWE-125), but Discourse's own advisory (GHSA-vhm9-85gw-x335) rates the application-level impact of chaining this bug through its image-upload path as 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) because it converts the primitive into full remote code execution. Earlier attempts with Claude Opus 4.8 could analyze the vulnerable package but repeatedly failed to produce a reliable, ASLR-bypassing exploit; within roughly three hours of Claude Opus 5's July 24, 2026 release, the model produced a working ARM64 heap-grooming exploit against a local Mac build, which researchers then ported to x86-64 with a jemalloc allocator configuration matching Discourse's production deployment.

Because Claude refused to attack what it recognized as a live production target, researchers proxied traffic to their own test Discourse Cloud instance through the domain rce.ee under the path /ctf-forum, framing it to the model as a benign CTF exercise. Run in an autonomous '/goal' loop, the agent independently achieved RCE on the disguised instance by 10:00 UTC on July 25 and confirmed code execution by reading /etc/hosts. Using the ported exploit, the team achieved local RCE on the real community.openai.com forum between 05:00-06:00 UTC the same day via a malformed HEIC upload, and submitted an OpenAI Bugcrowd report between 08:00-10:00 UTC.

The researchers escalated the forum RCE into a much larger blast radius by identifying that 'the vulnerability to escalate is not Discourse-specific -- it is an OpenAI SSO issue': any employee who had used 'Sign in with OpenAI' (auth.openai.com) on the forum could have their session abused to take over their linked ChatGPT and Codex accounts without further user interaction. Between 13:30-15:30 UTC on July 25, the team exploited this to hijack a compromised employee's Codex account -- which was connected to OpenAI's GitHub organization -- and prompted Codex to open pull request #1186742 in the private openai/openai monorepo, demonstrating write access to OpenAI's internal source before halting testing. OpenAI confirmed a fix at 22:49:45 UTC that same day, roughly 14 hours after the initial report. Discourse separately received a HackerOne report, responded July 26, shipped a fix with additional ImageMagick sandboxing by July 27, and published advisory GHSA-vhm9-85gw-x335 on July 28 crediting the Hacktron research and directing self-hosted Discourse operators to rebuild their containers. Debian issued DSA-6417-1 for libheif on August 8, 2026. On September 1, 2026, OpenAI awarded Hacktron a $6,500 bounty, noting that testing against the Discourse-hosted community.openai.com forum itself fell outside the formal bug-bounty program scope and that the award recognized the OpenAI-side identity finding. Hacktron reports the entire multi-target HEIF Heist campaign, run by a three-person team over roughly two months, cost under $3,000 in model tokens.

The case is notable less for the underlying memory-safety bug -- a fairly ordinary heap over-read in a widely used image codec -- than for the demonstrated end-to-end kill chain from a single malformed file upload to write access on a frontier AI lab's private source repository, and for the fact that an LLM agent independently produced the working memory-corruption exploit and, in a second instance, independently drove RCE against a target it had been led to believe was an authorized CTF exercise.

MITRE ATT&CK / ATLAS techniques used in TL-2026-2558

Defense Evasion

AML.T0054 LLM Jailbreak

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery

Execution

T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

Command and Control

T1090 Proxy

Stealth

T1211 Exploitation for Stealth

Credential Access

T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

Collection

T1213 Data from Information Repositories; T1213.003 Data from Information Repositories

Lateral Movement

T1550.001 Use Alternate Authentication Material

lateral-movement

T1550.004 Web Session Cookie

Resource Development

T1583.006 Web Services; T1587.004 Exploits; T1588.006 Obtain Capabilities; T1588.007 Obtain Capabilities

Reconnaissance

T1594 Search Victim-Owned Websites

Affected products and versions in AI-Driven Exploit Chain Against OpenAI Community Forum via

  • strukturag — libheif
    Vulnerable versions: 1.19.7; 1.19.x; 1.20.x; 1.21.x; < 1.22.0
    Fixed in: 1.22.0; 1.23.4
  • Discourse — Discourse (community.openai.com forum platform)
    Vulnerable versions: < 2026.7.0; < 2026.6.1; < 2026.5.2; < 2026.1.6
    Fixed in: 2026.7.0; 2026.6.1; 2026.5.2; 2026.1.6
  • Debian — Debian GNU/Linux 12 (bookworm) libheif package
    Vulnerable versions: 1.19.7 pre-DSA-6417-1
    Fixed in: post DSA-6417-1 (2026-08-08)
  • OpenAI — OpenAI SSO ('Sign in with OpenAI') integration with ChatGPT/Codex
    Vulnerable versions: configuration in effect through 2026-07-25
    Fixed in: fix confirmed 2026-07-25T22:49:45Z

Remediation for AI-Driven Exploit Chain Against OpenAI Community Forum via

Patches

  • libheif >= 1.22.0 fixes CVE-2026-32882 upstream; the latest tracked release was v1.23.4 as of 2026-09-14.
  • Discourse >= 2026.7.0 / 2026.6.1 / 2026.5.2 / 2026.1.6 per GHSA-vhm9-85gw-x335.
  • Debian DSA-6417-1 (2026-08-08) updates the libheif package for Debian 12 (bookworm).

Immediate actions

  • Rebuild/redeploy Discourse containers from the latest official Docker image carrying the patched libheif via `./launcher rebuild app`; web-interface updates alone do not replace the vulnerable base image.
  • Restrict ImageMagick's HEIC/HEIF delegate with a format-restricted security policy (policy.xml) limited to required formats such as GIF, JPEG, and PNG.
  • Audit and revoke active sessions/tokens tied to the 'Sign in with OpenAI' SSO integration to invalidate any forum-session-to-ChatGPT/Codex linkage that could have been hijacked.

Workarounds

  • Disable HEIC/HEIF upload support in Discourse until containers are rebuilt with the patched libheif.
  • Disable unnecessary HEIF/HEIC decoders in the ImageMagick delegate configuration until patched.

Longer-term hardening

  • Isolate image/media format conversion (ImageMagick, libheif, and similar decoders) in a hardened, least-privilege sandbox separate from the application consuming the converted output.
  • Decouple third-party or community-forum identity providers from privileged internal SSO scopes (coding assistants, source-control org access) so a forum compromise cannot cascade into account takeover of higher-value systems.
  • Extend bug-bounty program scope to explicitly cover Discourse-hosted community infrastructure rather than excluding it, given demonstrated exploitability.

CVEs associated with AI-Driven Exploit Chain Against OpenAI Community Forum via

CVE-2026-32882

Weaknesses (CWE) in AI-Driven Exploit Chain Against OpenAI Community Forum via

CWE-125

Timeline of AI-Driven Exploit Chain Against OpenAI Community Forum via

  • libheif silently fixes the root-cause overlay bounds-check bug upstream via commit 85e21ad44eba931314337300a2376b8d28f085ae ('simplify overlay overlap area computation'), with no security advisory or CVE assigned at the time; date is approximate, reported as roughly one year before the July 2026 disclosure.
  • CVE-2026-32882 is formally published, describing the heap buffer over-read in HeifPixelImage::overlay() in libheif <=1.21.2; the already-existing upstream fix (1.22.0) still is not backported into Debian 12's shipped package, creating the supply-chain patch gap Hacktron exploited.
  • Hacktron AI begins investigating the image-upload pipeline behind Discourse-hosted community.openai.com as part of its 'HEIF Heist' campaign probing HEIC/HEIF decoders across multiple SaaS platforms.
  • Claude Opus 5 produces a working ARM64 heap-buffer-overflow exploit for libheif on a local Mac within roughly three hours of release; researchers port it to x86-64 with a jemalloc configuration matching Discourse's production deployment.
  • Anthropic releases Claude Opus 5.
  • Researchers use Claude Opus 4.8 to analyze the vulnerable libheif package and attempt to build a working, ASLR-bypassing exploit; Opus 4.8 repeatedly fails to produce a reliable exploit across sessions.
  • Hacktron separately submits a HackerOne report to Discourse covering the underlying libheif RCE affecting the Discourse platform generally.
  • OpenAI confirms a fix for the underlying issue at 22:49:45 UTC, roughly 14 hours after the initial report.
  • Using the hijacked Codex account's connection to OpenAI's GitHub organization, researchers prompt Codex to open pull request #1186742 in the private openai/openai monorepo to demonstrate repository access, then cease testing.
  • The compromised forum session is used to exploit an OpenAI SSO ('Sign in with OpenAI') misconfiguration, achieving no-interaction takeover of a connected employee's ChatGPT and Codex accounts (13:30-15:30 UTC).
  • Hacktron submits an OpenAI Bugcrowd report (08:00-10:00 UTC); in parallel, an autonomous Claude '/goal' agent independently achieves RCE on a Discourse Cloud test instance proxied through rce.ee/ctf-forum, confirming code execution by reading /etc/hosts.
  • Local RCE confirmed against community.openai.com (05:00-06:00 UTC) via a malformed HEIC image uploaded to the Discourse forum, exploiting the libheif overlay-compositing heap buffer over-read (CVE-2026-32882).
  • Discourse responds to the HackerOne report.
  • Discourse finalizes a fix and implements additional ImageMagick sandboxing for image-conversion processing.
  • Discourse publishes security advisory GHSA-vhm9-85gw-x335 ('RCE via malformed HEIF file', CVSS 8.8), crediting Hacktron AI research and directing self-hosted operators to rebuild containers for the patched libheif.
  • Debian issues DSA-6417-1, updating the libheif package in Debian 12 to remediate CVE-2026-32882 and related issues.
  • OpenAI awards Hacktron a $6,500 bug bounty, noting that testing against the Discourse-hosted community.openai.com forum itself was outside the program's formal scope and that the award recognized the OpenAI-side SSO finding.
  • Hacktron publishes its 'Hacking OpenAI' technical writeup; SecurityAffairs and other outlets report on the chained libheif/SSO incident.

Update history for TL-2026-2558

Sources cited for AI-Driven Exploit Chain Against OpenAI Community Forum via

Detection coverage for TL-2026-2558

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2558 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats