www.securityweek.com 18 Sept 2026, 12:45 UTC

AI-Built Exploit Hijacked OpenAI Accounts Through Forum Images

AI-Built Exploit Hijacked OpenAI Accounts Through Forum Images
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS at security firm Hacktron used Anthropic’s Claude models to develop a working exploit for an unpatched vulnerability in the libheif library, which ImageMagick used to process HEIC/HEIF images uploaded to OpenAI’s Discourse-based community forum. The upstream bug had reportedly been fixed about a year earlier but was not identified as a security issue, so it had no CVE and missed normal patching processes. The exploit enabled remote code execution and was demonstrated first against a test Discourse installation and then against OpenAI’s forum.

Hacktron chained this access with a separate OpenAI sign-in flaw. Tokens issued for community.openai.com had excessive permissions, providing full API access to linked ChatGPT and Codex accounts. The researchers said this could have enabled the takeover of accounts belonging to forum users and employees, with possible further exposure through connected services such as GitHub, Slack and email.

To limit testing, they accessed an employee account linked to OpenAI’s GitHub organisation and opened a pull request in an internal repository. OpenAI said its review found limited reads of private-repository metadata and commits, followed by a researcher-created pull request changing only a README; it said Slack message access was not verified.

Hacktron reported the OpenAI issue through Bugcrowd, and OpenAI confirmed a fix roughly 14 hours later, narrowed community-token permissions and revoked affected tokens and sessions. The company paid a $6,500 bounty. Discourse fixed the libheif issue within two days, added image-processing sandboxing and published a security advisory.

View full article

Article by CyberSIXT