A team of security researchers was able to break into OpenAI's internal coding repository within hours of the release of Anthropic's Claude Opus 5 last July, leveraging a chain of vulnerabilities in an innocuous forum-hosting software application.
The team at Hacktron discovered a heap overflow vulnerability in libheif, a popular open-source image parser used to process HEIF and AVIF images, and used that to infiltrate OpenAI's implementation of Discourse with help from Opus 5, they announced Thursday. Once they had access to Discourse, they took advantage of a poorly configured SSO (single sign-on) implementation to take over an OpenAI employee's account, which granted it access to OpenAI's GitHub account.
"Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over," the researchers wrote. "The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours."