Threat reportVulnerabilityTL-2026-2558
AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)
AI-Driven Exploit Chain Against OpenAI Community Forum via (TL-2026-2558), also tracked as HEIF Heist, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-09-18 and last reviewed 2026-09-27. It is attributed to Hacktron AI with high confidence, affects strukturag libheif, references 1 CVE (CVE-2026-32882), maps to 23 MITRE ATT&CK / ATLAS techniques (AML.T0054, T1016, T1059), and is covered by 9 detection rules and 28 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 23MITRE ATT&CK / ATLAS
- Actors
- 1Hacktron AI
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-2558
- Threat ID
- TL-2026-2558
- Also known as
- HEIF Heist, Hacking OpenAI
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- Hacktron AI
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, software development, artificial intelligence
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 28
- Updates
- 2026-09-27 · 2 updates · revalidated 2× · latest source
Malware and tooling in AI-Driven Exploit Chain Against OpenAI Community Forum via
Malware and tooling: Bugcrowd, ChatGPT, Claude Opus 4.8, Claude Opus 5, HackerOne, OpenAI Codex
How AI-Driven Exploit Chain Against OpenAI Community Forum via works
Hacktron AI researchers used Claude Opus 5 to autonomously develop a heap-overflow exploit for CVE-2026-32882, a libheif overlay-compositing OOB read in Debian 12's Discourse Docker image, achieving RCE on OpenAI's community.openai.com forum via a malformed HEIC upload. A subsequent OpenAI SSO misconfiguration let the compromised forum session hijack a connected employee's ChatGPT/Codex accounts and open a pull request in OpenAI's private GitHub monorepo.
In July 2026, researchers at Hacktron AI (Harsh Jaiswal, Mohan Pedhapati, Rahul Maini) targeted the Discourse-hosted community.openai.com support forum as part of a broader campaign the firm calls 'HEIF Heist,' which probed HEIC/HEIF image-decoding pipelines across Slack, Meta, GitHub Enterprise, Ruby on Rails, Next.js, Astro, Gatsby, and Zoom. Discourse's Docker image (based on Debian 12) shipped libheif 1.19.7, which was missing an upstream heap-overflow backport, and Discourse's upload pipeline invoked ImageMagick's `magick` utility to convert HEIC/HEIF images -- a format FastImage could not validate -- routing untrusted attacker-controlled files directly into the vulnerable libheif decoder.
The root technical flaw the researchers weaponized is tracked as CVE-2026-32882: a heap buffer over-read in `HeifPixelImage::overlay()` (libheif/pixelimage.cc), which indexes an overlay image's alpha plane using the color-channel stride instead of the correct alpha stride when the two channels have mismatched bit depths, reading up to 3,123 bytes past the end of the alpha buffer for a 100x50 image mixing 10-bit color and 8-bit alpha. NVD rates the underlying library bug 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H, CWE-125), but Discourse's own advisory (GHSA-vhm9-85gw-x335) rates the application-level impact of chaining this bug through its image-upload path as 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) because it converts the primitive into full remote code execution. Earlier attempts with Claude Opus 4.8 could analyze the vulnerable package but repeatedly failed to produce a reliable, ASLR-bypassing exploit; within roughly three hours of Claude Opus 5's July 24, 2026 release, the model produced a working ARM64 heap-grooming exploit against a local Mac build, which researchers then ported to x86-64 with a jemalloc allocator configuration matching Discourse's production deployment.
Because Claude refused to attack what it recognized as a live production target, researchers proxied traffic to their own test Discourse Cloud instance through the domain rce.ee under the path /ctf-forum, framing it to the model as a benign CTF exercise. Run in an autonomous '/goal' loop, the agent independently achieved RCE on the disguised instance by 10:00 UTC on July 25 and confirmed code execution by reading /etc/hosts. Using the ported exploit, the team achieved local RCE on the real community.openai.com forum between 05:00-06:00 UTC the same day via a malformed HEIC upload, and submitted an OpenAI Bugcrowd report between 08:00-10:00 UTC.
The researchers escalated the forum RCE into a much larger blast radius by identifying that 'the vulnerability to escalate is not Discourse-specific -- it is an OpenAI SSO issue': any employee who had used 'Sign in with OpenAI' (auth.openai.com) on the forum could have their session abused to take over their linked ChatGPT and Codex accounts without further user interaction. Between 13:30-15:30 UTC on July 25, the team exploited this to hijack a compromised employee's Codex account -- which was connected to OpenAI's GitHub organization -- and prompted Codex to open pull request #1186742 in the private openai/openai monorepo, demonstrating write access to OpenAI's internal source before halting testing. OpenAI confirmed a fix at 22:49:45 UTC that same day, roughly 14 hours after the initial report. Discourse separately received a HackerOne report, responded July 26, shipped a fix with additional ImageMagick sandboxing by July 27, and published advisory GHSA-vhm9-85gw-x335 on July 28 crediting the Hacktron research and directing self-hosted Discourse operators to rebuild their containers. Debian issued DSA-6417-1 for libheif on August 8, 2026. On September 1, 2026, OpenAI awarded Hacktron a $6,500 bounty, noting that testing against the Discourse-hosted community.openai.com forum itself fell outside the formal bug-bounty program scope and that the award recognized the OpenAI-side identity finding. Hacktron reports the entire multi-target HEIF Heist campaign, run by a three-person team over roughly two months, cost under $3,000 in model tokens.
The case is notable less for the underlying memory-safety bug -- a fairly ordinary heap over-read in a widely used image codec -- than for the demonstrated end-to-end kill chain from a single malformed file upload to write access on a frontier AI lab's private source repository, and for the fact that an LLM agent independently produced the working memory-corruption exploit and, in a second instance, independently drove RCE against a target it had been led to believe was an authorized CTF exercise.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2558
Defense Evasion
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship
Command and Control
Stealth
T1211 Exploitation for Stealth
Credential Access
T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
Collection
T1213 Data from Information Repositories; T1213.003 Data from Information Repositories
Lateral Movement
T1550.001 Use Alternate Authentication Material
lateral-movement
Resource Development
T1583.006 Web Services; T1587.004 Exploits; T1588.006 Obtain Capabilities; T1588.007 Obtain Capabilities
Reconnaissance
Affected products and versions in AI-Driven Exploit Chain Against OpenAI Community Forum via
- strukturag — libheif
Vulnerable versions: 1.19.7; 1.19.x; 1.20.x; 1.21.x; < 1.22.0
Fixed in: 1.22.0; 1.23.4 - Discourse — Discourse (community.openai.com forum platform)
Vulnerable versions: < 2026.7.0; < 2026.6.1; < 2026.5.2; < 2026.1.6
Fixed in: 2026.7.0; 2026.6.1; 2026.5.2; 2026.1.6 - Debian — Debian GNU/Linux 12 (bookworm) libheif package
Vulnerable versions: 1.19.7 pre-DSA-6417-1
Fixed in: post DSA-6417-1 (2026-08-08) - OpenAI — OpenAI SSO ('Sign in with OpenAI') integration with ChatGPT/Codex
Vulnerable versions: configuration in effect through 2026-07-25
Fixed in: fix confirmed 2026-07-25T22:49:45Z
Remediation for AI-Driven Exploit Chain Against OpenAI Community Forum via
Patches
- libheif >= 1.22.0 fixes CVE-2026-32882 upstream; the latest tracked release was v1.23.4 as of 2026-09-14.
- Discourse >= 2026.7.0 / 2026.6.1 / 2026.5.2 / 2026.1.6 per GHSA-vhm9-85gw-x335.
- Debian DSA-6417-1 (2026-08-08) updates the libheif package for Debian 12 (bookworm).
Immediate actions
- Rebuild/redeploy Discourse containers from the latest official Docker image carrying the patched libheif via `./launcher rebuild app`; web-interface updates alone do not replace the vulnerable base image.
- Restrict ImageMagick's HEIC/HEIF delegate with a format-restricted security policy (policy.xml) limited to required formats such as GIF, JPEG, and PNG.
- Audit and revoke active sessions/tokens tied to the 'Sign in with OpenAI' SSO integration to invalidate any forum-session-to-ChatGPT/Codex linkage that could have been hijacked.
Workarounds
- Disable HEIC/HEIF upload support in Discourse until containers are rebuilt with the patched libheif.
- Disable unnecessary HEIF/HEIC decoders in the ImageMagick delegate configuration until patched.
Longer-term hardening
- Isolate image/media format conversion (ImageMagick, libheif, and similar decoders) in a hardened, least-privilege sandbox separate from the application consuming the converted output.
- Decouple third-party or community-forum identity providers from privileged internal SSO scopes (coding assistants, source-control org access) so a forum compromise cannot cascade into account takeover of higher-value systems.
- Extend bug-bounty program scope to explicitly cover Discourse-hosted community infrastructure rather than excluding it, given demonstrated exploitability.
CVEs associated with AI-Driven Exploit Chain Against OpenAI Community Forum via
CVE-2026-32882
Weaknesses (CWE) in AI-Driven Exploit Chain Against OpenAI Community Forum via
Timeline of AI-Driven Exploit Chain Against OpenAI Community Forum via
- libheif silently fixes the root-cause overlay bounds-check bug upstream via commit 85e21ad44eba931314337300a2376b8d28f085ae ('simplify overlay overlap area computation'), with no security advisory or CVE assigned at the time; date is approximate, reported as roughly one year before the July 2026 disclosure.
- CVE-2026-32882 is formally published, describing the heap buffer over-read in HeifPixelImage::overlay() in libheif <=1.21.2; the already-existing upstream fix (1.22.0) still is not backported into Debian 12's shipped package, creating the supply-chain patch gap Hacktron exploited.
- Hacktron AI begins investigating the image-upload pipeline behind Discourse-hosted community.openai.com as part of its 'HEIF Heist' campaign probing HEIC/HEIF decoders across multiple SaaS platforms.
- Claude Opus 5 produces a working ARM64 heap-buffer-overflow exploit for libheif on a local Mac within roughly three hours of release; researchers port it to x86-64 with a jemalloc configuration matching Discourse's production deployment.
- Anthropic releases Claude Opus 5.
- Researchers use Claude Opus 4.8 to analyze the vulnerable libheif package and attempt to build a working, ASLR-bypassing exploit; Opus 4.8 repeatedly fails to produce a reliable exploit across sessions.
- Hacktron separately submits a HackerOne report to Discourse covering the underlying libheif RCE affecting the Discourse platform generally.
- OpenAI confirms a fix for the underlying issue at 22:49:45 UTC, roughly 14 hours after the initial report.
- Using the hijacked Codex account's connection to OpenAI's GitHub organization, researchers prompt Codex to open pull request #1186742 in the private openai/openai monorepo to demonstrate repository access, then cease testing.
- The compromised forum session is used to exploit an OpenAI SSO ('Sign in with OpenAI') misconfiguration, achieving no-interaction takeover of a connected employee's ChatGPT and Codex accounts (13:30-15:30 UTC).
- Hacktron submits an OpenAI Bugcrowd report (08:00-10:00 UTC); in parallel, an autonomous Claude '/goal' agent independently achieves RCE on a Discourse Cloud test instance proxied through rce.ee/ctf-forum, confirming code execution by reading /etc/hosts.
- Local RCE confirmed against community.openai.com (05:00-06:00 UTC) via a malformed HEIC image uploaded to the Discourse forum, exploiting the libheif overlay-compositing heap buffer over-read (CVE-2026-32882).
- Discourse responds to the HackerOne report.
- Discourse finalizes a fix and implements additional ImageMagick sandboxing for image-conversion processing.
- Discourse publishes security advisory GHSA-vhm9-85gw-x335 ('RCE via malformed HEIF file', CVSS 8.8), crediting Hacktron AI research and directing self-hosted operators to rebuild containers for the patched libheif.
- Debian issues DSA-6417-1, updating the libheif package in Debian 12 to remediate CVE-2026-32882 and related issues.
- OpenAI awards Hacktron a $6,500 bug bounty, noting that testing against the Discourse-hosted community.openai.com forum itself was outside the program's formal scope and that the award recognized the OpenAI-side SSO finding.
- Hacktron publishes its 'Hacking OpenAI' technical writeup; SecurityAffairs and other outlets report on the chained libheif/SSO incident.
Update history for TL-2026-2558
- 2026-09-27 — Claude Opus 5 Helps Researchers Weaponize libheif Heap Overflow (CVE-2026-32882) Into RCE, SSO Session Hijack and Internal Repo Access at OpenAI: What changed No field escalations. cvss_score 7.1 and exploitability POC_PUBLIC in the new report are the underlying-library NVD figures already superseded by the existing record's higher app-level CVSS 8.8/ACTIVE assessment, so neither is
- 2026-09-19 — Heap Buffer Overflow in libheif (CVE-2026-32882) Chained with OpenAI SSO Flaw to Hijack Staff ChatGPT/Codex Accounts via Discourse Forum: What changed No field escalations: the new report's exploitability (POC_PUBLIC) and attribution confidence (LOW, actor 'Unknown') are both weaker than the existing record's (ACTIVE / HIGH, 'Hacktron AI') and are not applied per the escalati
Sources cited for AI-Driven Exploit Chain Against OpenAI Community Forum via
Detection coverage for TL-2026-2558
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2558 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.