Curated internet, served daily

OpenAI Paid $6,500 for a Route Into Its Internal Repo

Hacktron chained an SSO misconfiguration in OpenAI's identity layer with a libheif RCE on community.openai.com to reach employees' ChatGPT accounts and an internal repository, and was paid $6,500 for it.

OpenAI Paid $6,500 for a Route Into Its Internal Repo

On July 25, 2026, the Hacktron team chained two vulnerabilities into a working takeover of several OpenAI employees’ ChatGPT accounts. Access to OpenAI’s internal repositories, and to everything else those accounts had connected, arrived less than 72 hours after first discovery.

The proof of access was deliberately unglamorous. They used one employee’s Codex to open pull request #1186742 in OpenAI’s internal monorepo, then ceased all testing at roughly 15:30 UTC. The stated reason was to avoid learning anything sensitive. Connectors on those accounts meant the theoretical reach included GitHub, Slack and email.

A harmless pull request and a hard stop at 15:30 UTC is more restraint than most bounty reports show. Proving reach without reading anything is the part of this story I would copy.

The chain had two halves: an SSO misconfiguration in OpenAI’s identity infrastructure, and remote code execution on community.openai.com, OpenAI’s own help forum, through libheif. Until two months before the report, any user or OpenAI employee signing in there could have had their ChatGPT and Codex accounts taken over.

The team did the exploit work with Claude models and has since expanded it into HEIF Heist, a multi-month trace of libheif across Slack, Meta, GitHub Enterprise, Ruby on Rails, and Node frameworks such as Next.js, Astro and Gatsby. Their conclusion is blunt: any application handling user-controlled images and accepting .heic, .heif or .avif is highly likely affected.

OpenAI confirmed the fix roughly 14 hours after the Bugcrowd submission and paid $6,500. Discourse replied on Sunday, had a fix ready by Monday, added image-processing sandboxing, and published GHSA-vhm9-85gw-x335 with patch and rebuild guidance.

The fine print, from OpenAI’s own comment: testing against the Discourse-hosted community.openai.com was explicitly excluded from its bounty program, so the money recognizes the OpenAI-side identity finding. Six and a half thousand dollars for a route into an internal monorepo is a small number.

What stays with me is the shape of the failure. The forum sat outside the perimeter, but its login was federated into OpenAI’s identity layer, so a bug in an image library became an account-takeover bug. A parser that touches untrusted bytes joins the login path the moment it sits behind a login form.

Boundaries drawn around servers instead of around libraries keep failing this way.

The picture to hold: a self-hosted Discourse container still running the vulnerable image while the forum’s web interface looks perfectly healthy. Discourse’s patch notice for self-hosters is one word — rebuild. If you run one, do that before anything else.

← Back to Daily