Researchers at Hacktron chained a third-party image-processing vulnerability with an OpenAI sign-in weakness to take over employee ChatGPT and Codex accounts and demonstrate access to an internal code repository.
The attack began at OpenAI’s Discourse-based community forum. When the forum received HEIC or HEIF images, unsupported files were passed to ImageMagick and an affected libheif decoder. Hacktron used Claude models to help develop a reliable exploit for an upstream bug that had been fixed about a year earlier but had not been treated as a security issue or assigned a CVE.
From forum code execution to account takeover
Remote code execution on the community forum became significantly more serious because users could sign in with their OpenAI accounts. The tokens issued for that connection carried excessive permissions, providing full API access to associated ChatGPT and Codex accounts instead of narrowly scoped forum authentication.
Hacktron demonstrated the impact by taking over an OpenAI employee account connected through Codex to the company’s GitHub organization. The researchers opened a pull request that modified a README file and then stopped testing. OpenAI said its review found limited reads of private-repository metadata and commits, followed by the researcher-created pull request.
The researchers also raised the possibility that connected services such as Slack could have been exposed, although OpenAI said access to employee Slack messages was not verified.
Rapid fixes, broader lessons
OpenAI confirmed a fix for the account-takeover issue roughly 14 hours after it was reported through Bugcrowd. The company narrowed the permissions on community sign-in tokens and revoked affected tokens and sessions. Discourse prepared a fix within two days and added image-processing sandboxing.
The chain shows how a modest service can become a high-value bridge when single sign-on tokens have privileges far beyond the service’s actual needs. It also demonstrates that upstream fixes can be missed when maintainers do not recognize or communicate their security impact.
What defenders should review
- Inventory OAuth and single sign-on integrations and reduce token scopes to the minimum required.
- Separate community, support and marketing services from production developer identities.
- Sandbox media-processing components and keep transitive libraries patched.
- Revoke active sessions after changing token scopes; configuration changes alone may not invalidate existing access.
- Alert on unusual repository actions originating from accounts tied to lower-trust services.
Sources
- SecurityWeek: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
- Hacktron: Hacking OpenAI
- Discourse security advisory GHSA-vhm9-85gw-x335
