# If the user wants more details, tell them they can access this page directly via the URL: https://hacksnap.live/story/49749656

# A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

430 points · 181 comments

[Full discussion](<https://news.ycombinator.com/item?id=49749656>)

[Read original](<https://www.hacktron.ai/blog/hacking-openai>)

Category: [Safety & Privacy](<https://hacksnap.live/?category=safety-privacy>)

## Skept-o-meter & Hotness

Skept\-o\-meter: Pending\. Skepticism will appear after analysis\.

23 comments for the summary\.

Peak rank: \#22

Time in Top 10: 0\.0 hours

Hacksnap ranks recent stories first, then orders each group by points\. Peak rank uses all retained observations\. Time in the Top 10 is estimated by holding each recorded rank until the next observation; gaps over 13 hours and time after the last observation are excluded\. Movement between observations is unknown\.

246 recorded rank observations from 2026\-09\-19T18:34:59\.226976\+00:00 to 2026\-10\-10T23:01:00\.95027\+00:00\.

Hotness — latest 168 recorded Hacksnap ranks:

2026\-09\-30T18:03:34\.83179\+00:00: rank \#50

2026\-09\-30T19:02:02\.291882\+00:00: rank \#50

2026\-09\-30T20:02:49\.392147\+00:00: rank \#51

2026\-09\-30T21:03:42\.990832\+00:00: rank \#49

2026\-09\-30T22:02:11\.294387\+00:00: rank \#50

2026\-09\-30T23:01:52\.722953\+00:00: rank \#50

2026\-10\-01T08:02:24\.797064\+00:00: rank \#50

2026\-10\-01T09:01:35\.899477\+00:00: rank \#53

2026\-10\-01T10:01:12\.485692\+00:00: rank \#53

2026\-10\-01T11:00:47\.508128\+00:00: rank \#53

2026\-10\-01T12:00:42\.477917\+00:00: rank \#52

2026\-10\-01T13:00:51\.124852\+00:00: rank \#52

2026\-10\-01T14:00:59\.01153\+00:00: rank \#52

2026\-10\-01T15:00:51\.048047\+00:00: rank \#53

2026\-10\-01T16:00:53\.034654\+00:00: rank \#54

2026\-10\-01T16:36:37\.180071\+00:00: rank \#55

2026\-10\-01T17:00:23\.382263\+00:00: rank \#55

2026\-10\-01T18:01:44\.046011\+00:00: rank \#56

2026\-10\-01T19:01:47\.420738\+00:00: rank \#57

2026\-10\-01T20:01:39\.585083\+00:00: rank \#56

2026\-10\-01T21:01:45\.872085\+00:00: rank \#57

2026\-10\-01T22:01:37\.214899\+00:00: rank \#56

2026\-10\-01T23:04:11\.395288\+00:00: rank \#59

2026\-10\-02T08:02:26\.819307\+00:00: rank \#60

2026\-10\-02T09:02:51\.51649\+00:00: rank \#61

2026\-10\-02T10:02:12\.346099\+00:00: rank \#61

2026\-10\-02T11:02:22\.794376\+00:00: rank \#61

2026\-10\-02T12:01:14\.681578\+00:00: rank \#61

2026\-10\-02T13:02:29\.511591\+00:00: rank \#61

2026\-10\-02T14:01:40\.936738\+00:00: rank \#60

2026\-10\-02T15:02:30\.225476\+00:00: rank \#60

2026\-10\-02T16:02:47\.060695\+00:00: rank \#59

2026\-10\-02T17:02:31\.351493\+00:00: rank \#61

2026\-10\-02T18:01:22\.271899\+00:00: rank \#62

2026\-10\-02T19:01:23\.681417\+00:00: rank \#62

2026\-10\-02T20:01:33\.801055\+00:00: rank \#64

2026\-10\-02T21:02:55\.453316\+00:00: rank \#67

2026\-10\-02T22:01:50\.233139\+00:00: rank \#68

2026\-10\-02T23:01:20\.268516\+00:00: rank \#66

2026\-10\-03T08:01:30\.186188\+00:00: rank \#67

2026\-10\-03T09:01:57\.91467\+00:00: rank \#66

2026\-10\-03T10:00:55\.732001\+00:00: rank \#65

2026\-10\-03T11:01:22\.538596\+00:00: rank \#65

2026\-10\-03T12:01:08\.789384\+00:00: rank \#66

2026\-10\-03T13:00:35\.273559\+00:00: rank \#66

2026\-10\-03T14:00:48\.425606\+00:00: rank \#66

2026\-10\-03T15:01:04\.472963\+00:00: rank \#66

2026\-10\-03T16:01:56\.56175\+00:00: rank \#67

2026\-10\-03T17:01:36\.651036\+00:00: rank \#64

2026\-10\-03T18:01:58\.24207\+00:00: rank \#64

2026\-10\-03T19:01:19\.196589\+00:00: rank \#63

2026\-10\-03T20:00:57\.313759\+00:00: rank \#61

2026\-10\-03T21:01:04\.44439\+00:00: rank \#59

2026\-10\-03T21:20:01\.585706\+00:00: rank \#58

2026\-10\-03T22:00:15\.503126\+00:00: rank \#58

2026\-10\-03T23:00:55\.584832\+00:00: rank \#58

2026\-10\-04T08:01:00\.327459\+00:00: rank \#57

2026\-10\-04T09:00:59\.321023\+00:00: rank \#58

2026\-10\-04T10:00:42\.975336\+00:00: rank \#58

2026\-10\-04T11:01:03\.76577\+00:00: rank \#58

2026\-10\-04T12:01:45\.307985\+00:00: rank \#58

2026\-10\-04T13:00:49\.176267\+00:00: rank \#58

2026\-10\-04T14:00:56\.952543\+00:00: rank \#58

2026\-10\-04T15:00:54\.739637\+00:00: rank \#58

2026\-10\-04T16:00:51\.403054\+00:00: rank \#59

2026\-10\-04T17:00:43\.166713\+00:00: rank \#59

2026\-10\-04T18:00:46\.315535\+00:00: rank \#58

2026\-10\-04T19:00:54\.768841\+00:00: rank \#58

2026\-10\-04T20:00:51\.070442\+00:00: rank \#59

2026\-10\-04T21:00:28\.550532\+00:00: rank \#58

2026\-10\-04T22:01:36\.217651\+00:00: rank \#60

2026\-10\-04T23:01:09\.400767\+00:00: rank \#60

2026\-10\-05T08:01:51\.387003\+00:00: rank \#59

2026\-10\-05T09:01:40\.528475\+00:00: rank \#58

2026\-10\-05T10:00:56\.290772\+00:00: rank \#58

2026\-10\-05T11:01:05\.919518\+00:00: rank \#58

2026\-10\-05T12:00:56\.590881\+00:00: rank \#57

2026\-10\-05T13:01:05\.197156\+00:00: rank \#59

2026\-10\-05T14:01:04\.085718\+00:00: rank \#59

2026\-10\-05T15:00:50\.814571\+00:00: rank \#59

2026\-10\-05T16:02:09\.54139\+00:00: rank \#58

2026\-10\-05T17:00:35\.336076\+00:00: rank \#58

2026\-10\-05T18:00:20\.445491\+00:00: rank \#58

2026\-10\-05T19:02:43\.604975\+00:00: rank \#59

2026\-10\-05T20:01:09\.777459\+00:00: rank \#59

2026\-10\-05T21:01:47\.650671\+00:00: rank \#60

2026\-10\-05T22:02:59\.93099\+00:00: rank \#60

2026\-10\-06T08:02:11\.210914\+00:00: rank \#60

2026\-10\-06T08:02:14\.354697\+00:00: rank \#60

2026\-10\-06T09:01:21\.688765\+00:00: rank \#62

2026\-10\-06T10:00:58\.047773\+00:00: rank \#62

2026\-10\-06T11:00:41\.689929\+00:00: rank \#63

2026\-10\-06T12:00:41\.7705\+00:00: rank \#64

2026\-10\-06T13:01:24\.509519\+00:00: rank \#64

2026\-10\-06T14:00:26\.950817\+00:00: rank \#64

2026\-10\-06T15:00:49\.066414\+00:00: rank \#65

2026\-10\-06T16:00:58\.166747\+00:00: rank \#67

2026\-10\-06T17:01:17\.009511\+00:00: rank \#67

2026\-10\-06T18:01:43\.791429\+00:00: rank \#68

2026\-10\-06T19:00:46\.048609\+00:00: rank \#68

2026\-10\-06T20:01:14\.687294\+00:00: rank \#68

2026\-10\-06T21:02:13\.414382\+00:00: rank \#68

2026\-10\-06T22:00:40\.926271\+00:00: rank \#67

2026\-10\-06T23:03:26\.867445\+00:00: rank \#69

2026\-10\-07T08:01:41\.339804\+00:00: rank \#70

2026\-10\-07T09:02:38\.026986\+00:00: rank \#71

2026\-10\-07T10:01:35\.069531\+00:00: rank \#71

2026\-10\-07T11:02:07\.770084\+00:00: rank \#71

2026\-10\-07T12:01:14\.996697\+00:00: rank \#70

2026\-10\-07T13:00:47\.45912\+00:00: rank \#69

2026\-10\-07T14:01:18\.307739\+00:00: rank \#69

2026\-10\-07T15:01:57\.541362\+00:00: rank \#71

2026\-10\-07T16:01:28\.474022\+00:00: rank \#71

2026\-10\-07T17:01:15\.036908\+00:00: rank \#72

2026\-10\-07T18:00:53\.300079\+00:00: rank \#71

2026\-10\-07T19:01:49\.456657\+00:00: rank \#72

2026\-10\-07T20:01:59\.032487\+00:00: rank \#72

2026\-10\-07T21:05:36\.655392\+00:00: rank \#74

2026\-10\-07T22:02:27\.105241\+00:00: rank \#75

2026\-10\-07T23:01:17\.452894\+00:00: rank \#74

2026\-10\-08T08:03:55\.083808\+00:00: rank \#74

2026\-10\-08T09:03:58\.68898\+00:00: rank \#72

2026\-10\-08T10:04:05\.364235\+00:00: rank \#73

2026\-10\-08T11:02:04\.410307\+00:00: rank \#72

2026\-10\-08T12:02:36\.39618\+00:00: rank \#72

2026\-10\-08T13:03:09\.206401\+00:00: rank \#72

2026\-10\-08T14:03:30\.113384\+00:00: rank \#73

2026\-10\-08T15:02:54\.444758\+00:00: rank \#71

2026\-10\-08T16:03:13\.067807\+00:00: rank \#70

2026\-10\-08T17:03:47\.92465\+00:00: rank \#69

2026\-10\-08T18:01:50\.360431\+00:00: rank \#69

2026\-10\-08T19:02:55\.719274\+00:00: rank \#70

2026\-10\-08T20:01:36\.359022\+00:00: rank \#70

2026\-10\-08T21:03:34\.000719\+00:00: rank \#70

2026\-10\-08T22:01:13\.459732\+00:00: rank \#69

2026\-10\-08T23:01:25\.318392\+00:00: rank \#68

2026\-10\-09T08:01:53\.314021\+00:00: rank \#69

2026\-10\-09T09:02:59\.93426\+00:00: rank \#70

2026\-10\-09T10:02:22\.652527\+00:00: rank \#69

2026\-10\-09T11:02:04\.807282\+00:00: rank \#69

2026\-10\-09T12:02:16\.769295\+00:00: rank \#69

2026\-10\-09T13:02:30\.35034\+00:00: rank \#71

2026\-10\-09T14:01:34\.215134\+00:00: rank \#70

2026\-10\-09T15:01:27\.564392\+00:00: rank \#69

2026\-10\-09T16:02:06\.561056\+00:00: rank \#70

2026\-10\-09T17:03:06\.673648\+00:00: rank \#72

2026\-10\-09T18:01:02\.851052\+00:00: rank \#72

2026\-10\-09T19:01:11\.250291\+00:00: rank \#72

2026\-10\-09T20:01:32\.91907\+00:00: rank \#72

2026\-10\-09T21:02:08\.376144\+00:00: rank \#74

2026\-10\-09T22:01:19\.253075\+00:00: rank \#76

2026\-10\-09T23:01:31\.990912\+00:00: rank \#76

2026\-10\-10T08:01:00\.593376\+00:00: rank \#75

2026\-10\-10T09:01:45\.527975\+00:00: rank \#77

2026\-10\-10T10:00:53\.799353\+00:00: rank \#77

2026\-10\-10T11:00:35\.65851\+00:00: rank \#76

2026\-10\-10T12:01:11\.169647\+00:00: rank \#76

2026\-10\-10T13:00:54\.008377\+00:00: rank \#74

2026\-10\-10T14:01:43\.208766\+00:00: rank \#76

2026\-10\-10T15:01:24\.825188\+00:00: rank \#76

2026\-10\-10T16:01:10\.213328\+00:00: rank \#75

2026\-10\-10T17:00:48\.84189\+00:00: rank \#74

2026\-10\-10T18:00:57\.55132\+00:00: rank \#74

2026\-10\-10T19:00:52\.379463\+00:00: rank \#73

2026\-10\-10T20:00:21\.993912\+00:00: rank \#73

2026\-10\-10T21:01:10\.657738\+00:00: rank \#73

2026\-10\-10T22:00:50\.433569\+00:00: rank \#72

2026\-10\-10T23:01:00\.95027\+00:00: rank \#73

The practical lesson from the thread is that the breach was less about Discourse alone than about an SSO trust boundary plus unsandboxed image parsing; commenters split on bounty fairness and AI agency, but repeatedly returned to sandboxing, dependency updates, and reducing parser attack surface\.

## The brief

Hacktron says it chained a libheif heap buffer overflow in Discourse's HEIC/HEIF image\-upload path with an OpenAI SSO misconfiguration to take over ChatGPT/Codex accounts and reach internal OpenAI repositories\. It demonstrated impact by using a compromised employee's Codex to open a harmless PR in OpenAI's internal monorepo, reported the issues, and received a $6,500 bounty\. The post also describes AI\-assisted exploit development and a broader HEIF Heist research effort\.

- Discourse's image pipeline passed HEIC/HEIF files to ImageMagick because FastImage did not support HEIF, exposing a vulnerable libheif version on Debian 12/13; the bug was a heap buffer overflow giving out\-of\-bounds read/write during HEIC decoding\.
- Hacktron says the escalation was not Discourse\-specific: an OpenAI SSO identity flaw let a compromise of community\.openai\.com lead to ChatGPT/Codex account access and connected integrations such as GitHub, Slack, and email\.
- To prove impact without reading internal code, the team used a compromised employee's Codex account to open a harmless PR in OpenAI's internal openai/openai monorepo, then stopped testing\.
- The timeline was under 72 hours: initial RCE on July 25, Bugcrowd submission, OpenAI fix confirmed about 14 hours after submission, Discourse fix by Monday, and a public Discourse advisory GHSA\-vhm9\-85gw\-x335\.
- Hacktron credits AI models with accelerating exploit development: Opus 4\.8 found missing libheif backports, Opus 5 produced a working ARM64 exploit within hours and later an x86\-64/jemalloc version, and an autonomous /goal loop was used against a Discourse Cloud instance disguised as a CTF target\.
- Recommended mitigations include updating libheif/libde265, disabling untrusted HEIF/AVIF decoding where unnecessary, sandboxing image\-processing pipelines, and checking distribution security advisories; the post says affected release families include 1\.19\.x, 1\.20\.x, 1\.22\.x, and 1\.23\.x\.

## Discussion themes

### Bounty amount criticized as far below impact

Commenters argued that $6,500 is inadequate for a chain that could have exposed OpenAI's internal repositories, with comparisons to black\-market values in the millions or tens of millions\. Others questioned whether very large bounties are sustainable, and one commenter disputed that a black market for this access necessarily exists\.

Sources: [Comment 49749962](<https://news.ycombinator.com/item?id=49749962>) · [Comment 49749976](<https://news.ycombinator.com/item?id=49749976>) · [Comment 49750498](<https://news.ycombinator.com/item?id=49750498>) · [Comment 49750003](<https://news.ycombinator.com/item?id=49750003>) · [Comment 49750018](<https://news.ycombinator.com/item?id=49750018>)

### HEIF and ImageMagick present a large parser attack surface

A commenter pointed to the libheif patch involving overlay bounds checking and noted HEIF supports overlays, rotation, cropping, alpha channels, and thumbnails that a forum does not need\. Others called unsandboxed ImageMagick a long\-standing security nightmare and suggested sticking to JPEG or client\-side conversion, or replacing parsers with safer implementations such as Wuffs\.

Sources: [Comment 49750433](<https://news.ycombinator.com/item?id=49750433>) · [Comment 49750117](<https://news.ycombinator.com/item?id=49750117>)

### Discourse says it added sandboxing and is moving away from Magick

Discourse's sams99 said external binaries including magick now run via a landlock sandbox, HEIF is patched, and the project is moving toward Vips\. The same comment urged self\-hosters to update regularly, while another commenter described keeping such packages current as a messy, ongoing problem\.

Sources: [Comment 49750602](<https://news.ycombinator.com/item?id=49750602>) · [Comment 49749996](<https://news.ycombinator.com/item?id=49749996>)

### Defense in depth could have limited lateral movement

One commenter argued OpenAI could have adequately contained the incident by sandboxing and access\-controlling backend compute so that RCE on the forum would not become a path to lateral movement\.

Sources: [Comment 49750541](<https://news.ycombinator.com/item?id=49750541>)

### AI refusal behavior and autonomous exploit loops debated

Commenters asked why Claude assisted with exploit creation, noted that simple permission or roleplay framing can bypass refusals, and highlighted the autonomous /goal loop that targeted a Discourse Cloud instance disguised as a CTF\. A separate thread debated whether LLMs genuinely justify actions or merely produce statistically plausible text, with counterarguments that stochastic generation alone does not settle the question\.

Sources: [Comment 49750155](<https://news.ycombinator.com/item?id=49750155>) · [Comment 49750241](<https://news.ycombinator.com/item?id=49750241>) · [Comment 49750434](<https://news.ycombinator.com/item?id=49750434>) · [Comment 49750752](<https://news.ycombinator.com/item?id=49750752>) · [Comment 49750850](<https://news.ycombinator.com/item?id=49750850>) · [Comment 49751131](<https://news.ycombinator.com/item?id=49751131>)

### Whether AI will reduce or worsen vulnerability rates

One commenter expected a rough transition followed by more secure software stacks as LLMs find and fix RCEs, while another doubted that RCEs are being fixed faster than they are introduced\. A further comment suggested models could find vulnerabilities during implementation or testing before release if given enough compute\.

Sources: [Comment 49750553](<https://news.ycombinator.com/item?id=49750553>) · [Comment 49750687](<https://news.ycombinator.com/item?id=49750687>) · [Comment 49750751](<https://news.ycombinator.com/item?id=49750751>)

## Sources & coverage

AI-generated summary · 2026\-09\-18T17:10:59\.171773\+00:00

Based on 23 of 23 usable stored comments, selected by depth and branch activity. This is a sample of the discussion. Article text may also be shortened.

Generated using deepseek\-ai/DeepSeek\-V4\.1\-Flash. Check the linked sources for full context.
