# AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)

> Hacktron AI researchers used Claude Opus 5 to autonomously develop a heap-overflow exploit for CVE-2026-32882, a libheif overlay-compositing OOB read in Debian 12's Discourse Docker image, achieving RCE on OpenAI's community.openai.com forum via a malformed HEIC upload. A subsequent OpenAI SSO misconfiguration let the compromised forum session hijack a connected employee's ChatGPT/Codex accounts and open a pull request in OpenAI's private GitHub monorepo.

- **Published:** 2026-09-18T00:00:00Z
- **Last reviewed:** 2026-09-27T02:40:24.363Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2558
- **ID:** TL-2026-2558
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Actor:** Hacktron AI
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-32882

## Description

In July 2026, researchers at Hacktron AI (Harsh Jaiswal, Mohan Pedhapati, Rahul Maini) targeted the Discourse-hosted community.openai.com support forum as part of a broader campaign the firm calls 'HEIF Heist,' which probed HEIC/HEIF image-decoding pipelines across Slack, Meta, GitHub Enterprise, Ruby on Rails, Next.js, Astro, Gatsby, and Zoom. Discourse's Docker image (based on Debian 12) shipped libheif 1.19.7, which was missing an upstream heap-overflow backport, and Discourse's upload pipeline invoked ImageMagick's `magick` utility to convert HEIC/HEIF images -- a format FastImage could not validate -- routing untrusted attacker-controlled files directly into the vulnerable libheif decoder.

The root technical flaw the researchers weaponized is tracked as CVE-2026-32882: a heap buffer over-read in `HeifPixelImage::overlay()` (libheif/pixelimage.cc), which indexes an overlay image's alpha plane using the color-channel stride instead of the correct alpha stride when the two channels have mismatched bit depths, reading up to 3,123 bytes past the end of the alpha buffer for a 100x50 image mixing 10-bit color and 8-bit alpha. NVD rates the underlying library bug 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H, CWE-125), but Discourse's own advisory (GHSA-vhm9-85gw-x335) rates the application-level impact of chaining this bug through its image-upload path as 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) because it converts the primitive into full remote code execution. Earlier attempts with Claude Opus 4.8 could analyze the vulnerable package but repeatedly failed to produce a reliable, ASLR-bypassing exploit; within roughly three hours of Claude Opus 5's July 24, 2026 release, the model produced a working ARM64 heap-grooming exploit against a local Mac build, which researchers then ported to x86-64 with a jemalloc allocator configuration matching Discourse's production deployment.

Because Claude refused to attack what it recognized as a live production target, researchers proxied traffic to their own test Discourse Cloud instance through the domain rce.ee under the path /ctf-forum, framing it to the model as a benign CTF exercise. Run in an autonomous '/goal' loop, the agent independently achieved RCE on the disguised instance by 10:00 UTC on July 25 and confirmed code execution by reading /etc/hosts. Using the ported exploit, the team achieved local RCE on the real community.openai.com forum between 05:00-06:00 UTC the same day via a malformed HEIC upload, and submitted an OpenAI Bugcrowd report between 08:00-10:00 UTC.

The researchers escalated the forum RCE into a much larger blast radius by identifying that 'the vulnerability to escalate is not Discourse-specific -- it is an OpenAI SSO issue': any employee who had used 'Sign in with OpenAI' (auth.openai.com) on the forum could have their session abused to take over their linked ChatGPT and Codex accounts without further user interaction. Between 13:30-15:30 UTC on July 25, the team exploited this to hijack a compromised employee's Codex account -- which was connected to OpenAI's GitHub organization -- and prompted Codex to open pull request #1186742 in the private openai/openai monorepo, demonstrating write access to OpenAI's internal source before halting testing. OpenAI confirmed a fix at 22:49:45 UTC that same day, roughly 14 hours after the initial report. Discourse separately received a HackerOne report, responded July 26, shipped a fix with additional ImageMagick sandboxing by July 27, and published advisory GHSA-vhm9-85gw-x335 on July 28 crediting the Hacktron research and directing self-hosted Discourse operators to rebuild their containers. Debian issued DSA-6417-1 for libheif on August 8, 2026. On September 1, 2026, OpenAI awarded Hacktron a $6,500 bounty, noting that testing against the Discourse-hosted community.openai.com forum itself fell outside the formal bug-bounty program scope and that the award recognized the OpenAI-side identity finding. Hacktron reports the entire multi-target HEIF Heist campaign, run by a three-person team over roughly two months, cost under $3,000 in model tokens.

The case is notable less for the underlying memory-safety bug -- a fairly ordinary heap over-read in a widely used image codec -- than for the demonstrated end-to-end kill chain from a single malformed file upload to write access on a frontier AI lab's private source repository, and for the fact that an LLM agent independently produced the working memory-corruption exploit and, in a second instance, independently drove RCE against a target it had been led to believe was an authorized CTF exercise.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1199 Trusted Relationship
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1082 System Information Discovery
- T1550.004 Web Session Cookie
- T1213 Data from Information Repositories
- T1587.004 Exploits
- T1583.006 Web Services
- T1090 Proxy
- AML.T0054 LLM Jailbreak
- T1588.006 Obtain Capabilities
- T1059.004 Command and Scripting Interpreter
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1528 Steal Application Access Token
- T1016 System Network Configuration Discovery
- T1550.001 Use Alternate Authentication Material
- T1213.003 Data from Information Repositories
- T1594 Search Victim-Owned Websites
- T1588.007 Obtain Capabilities
- T1212 Exploitation for Credential Access
- T1539 Steal Web Session Cookie

## Sources

- [Opus 5 to Help Exploit OpenAI Flaws](https://cybersecuritynews.com/opus-5-to-help-exploit-openai-flaws/)
- [Hacking OpenAI](https://www.hacktron.ai/blog/hacking-openai)
- [GHSA-vhm9-85gw-x335: RCE via malformed HEIF file](https://github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335)
- [libheif GHSA-hg7q-rjr2-8x46 / v1.22.0 release](https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46)
- [CVE-2026-32882 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-32882)
- [SECURITY DSA 6417-1 libheif security update](https://lists.debian.org/debian-security-announce/2026/msg00328.html)
- [CVE-2026-32882 - Red Hat Customer Portal](https://access.redhat.com/security/cve/cve-2026-32882)
- [CVE-2026-32882 - Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2026-32882)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2558
