# AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access

> Security firm Hacktron AI used Claude Opus (4.8, then Opus 5) to build a working exploit for an unflagged libheif heap buffer overflow reachable through ImageMagick's HEIC/HEIF handling on OpenAI's Discourse forum, then chained it with an OpenAI sign-in-token flaw to take over an employee's ChatGPT/Codex account and reach OpenAI's internal GitHub monorepo. OpenAI confirmed a fix in ~14 hours and paid a $6,500 bounty; Discourse shipped a patch within two days.

- **Published:** 2026-09-18T00:00:00Z
- **Last reviewed:** 2026-09-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2568
- **ID:** TL-2026-2568
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Actor:** Hacktron AI
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On July 25, 2026, three-person security research startup Hacktron AI chained two previously unknown weaknesses to reach internal OpenAI infrastructure in an authorized bug-bounty engagement. OpenAI's community forum (community.openai.com, built on Discourse) used FastImage to validate uploaded images, but FastImage does not recognize HEIC/HEIF files -- Apple's default photo formats -- so any HEIC/HEIF upload was instead handed to ImageMagick's `magick` CLI, which in turn invoked the native libheif decoder. The Discourse Docker image (Debian 12 base) shipped libheif 1.19.7, which contained a heap buffer overflow in the overlay-compositing path of `HeifPixelImage::overlay()`, producing out-of-bounds read/write primitives during HEIC decoding. The underlying bug had actually been fixed upstream roughly a year earlier via commit 85e21ad44 ("simplify overlay overlap area computation"), but the fix was never flagged as security-relevant, received no CVE, and was consequently never backported by Debian, leaving Discourse's container exposed with no visible patch trail to follow.

Hacktron began reconnaissance of Discourse's image pipeline on July 23, 2026. Claude Opus 4.8 was used across several sessions to attempt exploit development but could not reliably defeat ASLR on the target. Anthropic released Claude Opus 5 on July 24, 2026, and within hours of the release Hacktron re-ran the same exploitation problem: Opus 5 produced a working ARM64 exploit against a local macOS target within about three hours, which the team then ported to x86-64 and tuned for Discourse's production jemalloc heap layout. Local RCE via a crafted HEIC upload was confirmed around 05:00-06:00 UTC on July 25, and an autonomous agent loop achieved RCE against OpenAI's live Discourse Cloud instance by roughly 10:00 UTC the same day, verified by reading `/etc/hosts` inside the compromised container. To keep Opus from refusing to test an apparently non-consented remote target, the team fronted the live attack through a proxy testing domain (rce.ee/ctf-forum) that gave the agent a context it would treat as in-scope.

Forum compromise alone would only have yielded a Discourse admin/RCE foothold, but OpenAI's "Sign in with OpenAI" integration (routed through auth.openai.com) issued forum sign-in tokens with excessive scope: a token minted for community.openai.com carried full API access to the same user's ChatGPT and Codex accounts. Using the RCE foothold to obtain an authenticated employee's forum session, Hacktron converted that session into a live ChatGPT/Codex API credential for the employee -- effectively an account takeover with no additional verification step. Because the employee's Codex account was itself connected to OpenAI's internal GitHub organization, the researchers prompted the hijacked Codex session to open a deliberately benign pull request (PR #1186742) in OpenAI's internal `openai/openai` monorepo as proof of write access, and separately confirmed read access to private repository metadata, commit history, and README content. No Slack access was verified despite Slack being among the employee's other connected services. Testing stopped once the PoC PR was opened.

Hacktron reported the OpenAI SSO/token-scope issue via Bugcrowd and the Discourse/libheif RCE via HackerOne on July 25. OpenAI confirmed and deployed a fix to the token-scope flaw by 22:49 UTC the same day (about 14 hours after the report) and later paid a $6,500 bounty, awarded September 1, 2026; the Discourse-side findings were out of scope for that bounty. Discourse responded to the HackerOne report on July 26, had a fix ready July 27, and publicly shipped patched builds (2026.7.0, 2026.6.1, 2026.5.2, 2026.1.6, pinning libheif 1.23.4 and adding ImageMagick process sandboxing) alongside advisory GHSA-vhm9-85gw-x335 (CVSS 8.8) on July 28, 2026, warning self-hosted operators that a web-interface update alone would not replace the vulnerable base image. Hacktron publicly disclosed the full chain on September 18, 2026, as one case study within a broader campaign they call "HEIF Heist" -- a months-long investigation into libheif and the related libde265 decoder that the team says also reached Slack, Meta, GitHub Enterprise (CVE-2026-19118), Rails, Next.js (unauthenticated RCE via AVIF Image Optimization), and other ImageMagick-fronted deployments, spanning libheif release families 1.19.x through 1.23.x, at a reported total AI-token cost of under $3,000 across roughly two months; Hacktron says thousands of crafted uploads were sometimes needed per target, and that aside from this incident they are aware of only one company (Shopify, unrelated to the OpenAI chain) that detected the probing activity. No CVE has been assigned to the specific overlay() heap overflow Hacktron exploited (1.19.7, silently fixed pre-1.19.8). Note for correlation, confirmed against primary sources: a separate, earlier-disclosed libheif flaw -- CVE-2026-32882 / GHSA-hg7q-rjr2-8x46, an out-of-bounds read in the same HeifPixelImage::overlay() function caused by using the color-channel stride (in_stride) instead of the correct alpha stride (alpha_stride) at pixelimage.cc line 1835, affecting versions <=1.21.2 and fixed in 1.22.0 (released May 19, 2026; CVSS 7.1, AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H -- a read-only info-disclosure/DoS bug with no integrity impact) -- is DISTINCT from the flaw Hacktron actually exploited. Discourse's own advisory GHSA-vhm9-85gw-x335 nonetheless names CVE-2026-32882 as the vulnerability it patched, which reads as a mislabeling by Discourse (citing the nearest known CVE against the same overlay() function) rather than evidence the two bugs are identical: Discourse's advisory carries its own independently-assigned CVSS of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), an RCE-shaped vector with full integrity impact inconsistent with CVE-2026-32882's read-only, user-interaction-required profile, and instead matches Hacktron's description of write-capable out-of-bounds primitives from the unflagged, CVE-less commit 85e21ad44 fix. Analysts correlating this threat should treat CVE-2026-32882 as related-but-not-identical and flag Discourse's advisory text itself as a source of the conflation.

## MITRE ATT&CK

- T1592.002 Software
- T1587.004 Exploits
- T1583.006 Web Services
- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1082 System Information Discovery
- T1526 Cloud Service Discovery
- T1528 Steal Application Access Token
- T1550.001 Application Access Token
- T1213.003 Code Repositories
- AML.T0054 LLM Jailbreak

## Sources

- [AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code](https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/)
- [Hacking OpenAI](https://www.hacktron.ai/blog/hacking-openai)
- [From a Single Image to OpenAI Monorepo: How a libheif Heap Overflow and SSO Flaw Chained to PR #1186742](https://lilting.ch/en/articles/openai-hacktron-discourse-libheif-sso)
- [Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories](https://cybersecuritynews.com/opus-5-to-help-exploit-openai-flaws/)
- [OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5](https://venturebeat.com/security/openai-hacked-by-small-team-of-white-hat-security-researchers-using-anthropics-claude-opus-5)
- [Three Indian researchers used Claude to hack into OpenAI in under 72 hours](https://thetechportal.com/2026/09/18/openai-hacked-using-claude-hacktron-ai-indian-security-researchers)
- [HEIF Heist](https://heif-heist.com/)
- [We're disclosing HEIF Heist, a months-long investigation into libheif](https://x.com/rootxharsh/status/2100801820960620574)
- [Vulnerable libheif in Discourse Docker (Debian missing a security backport) -- GHSA-vhm9-85gw-x335, CVSS 8.8; advisory text cites CVE-2026-32882, which appears to be a mislabeling given the mismatched CVSS/impact profile](https://github.com/discourse/discourse/security/advisories/GHSA-vhm9-85gw-x335)
- [SECURITY DSA 6417-1 libheif security update](https://lists.debian.org/debian-security-announce/2026/msg00328.html)
- [Heap Buffer OOB Read in overlay compositing due to wrong alpha stride -- GHSA-hg7q-rjr2-8x46 (related but distinct from the exploited flaw)](https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46)
- [CVE-2026-32882 (related but distinct libheif overlay() OOB read, fixed in 1.22.0)](https://access.redhat.com/security/cve/cve-2026-32882)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2568
