Overview
- Researchers at Hacktron developed a working exploit for a libheif image-decoding flaw in Discourse’s image pipeline and used it to run code on OpenAI’s community forum.
- The team chained that remote code execution to an overprivileged OpenAI SSO token that granted API access to ChatGPT and Codex accounts, allowing control of an employee-linked account and a harmless internal pull request as proof.
- The libheif bug had been fixed upstream months earlier but the forum’s Debian-based server image still ran an older libheif, showing distribution and container rebuild delays left the site exposed.
- Hacktron says Anthropic’s Claude Opus 5 and other frontier models materially sped exploit work, cutting tasks that once took weeks down to roughly one to three days during their tests.
- OpenAI narrowed token scopes, revoked affected sessions, paid a $6,500 bounty for the OpenAI-side finding, and Discourse issued patches and added image-processing sandboxing while broader HEIF Heist claims remain under investigation.