Claude Opus 5 Helped Hacktron Chain Discourse libheif RCE into OpenAI Staff Account Access remote code execution flaw (CVE-2026-32882)
Vulnerability
Summary
Hide ▲
Show ▼
Discourse HEIC/HEIF upload processing is tied to CVE-2026-32882, a flaw that Discourse rates as remote code execution with an 8.8/10 severity score. The issue sits in the libheif path used after uploads are handed to ImageMagick, and the affected OpenAI forum path was described as community.openai.com. Hacktron says it chained the bug with OpenAI's login flow to reach ChatGPT and Codex accounts for several OpenAI employees and access an internal code repository, but OpenAI says the work was a controlled report, fixed the issue in about 14 hours, and paid a $6,500 bounty.
Related Happenings
OpenAI Codex sandbox escape fixes in Desktop and CLI
Security Tool/Service
H score11
First: 20.09.2026 15:00
Last: 20.09.2026 15:00
Sources 1
About this happening:
OpenAI fixed Heapjack in Codex Desktop and Overpatch in Codex CLI, closing sandbox escapes that could let untrusted agent activity reach a developer's host. The fl...
OpenAI Codex sandbox escape fixes in Desktop and CLI
Security Tool/ServiceAbout this happening: OpenAI fixed Heapjack in Codex Desktop and Overpatch in Codex CLI, closing sandbox escapes that could let untrusted agent activity reach a developer's host. The fl...
OpenAI hit by account takeover attack
Incident
H score18
First: 18.09.2026 15:45
Last: 18.09.2026 15:45
Sources 1
How related:
To demonstrate the access without reading any internal code, Hacktron says it took over an OpenAI employee’s account whose Codex integration was linked to OpenAI’s GitHub organization, then used it to open a pull request in an internal repository before stopping further testing.
About this happening:
OpenAI suffered an employee account takeover that led to internal repository access and limited reads of private-repository metadata and commits. The access path ran t...
OpenAI hit by account takeover attack
IncidentHow related: To demonstrate the access without reading any internal code, Hacktron says it took over an OpenAI employee’s account whose Codex integration was linked to OpenAI’s GitHub organization, then used it to open a pull request in an internal repository before stopping further testing.
About this happening: OpenAI suffered an employee account takeover that led to internal repository access and limited reads of private-repository metadata and commits. The access path ran t...
AI coding agents plugin pinning bypass security flaw
Vulnerability
H score60
First: 18.09.2026 14:01
Last: 18.09.2026 14:01
Sources 1
About this happening:
Plugin pinning bypass in four AI coding agents lets a repository owner swap a supposedly reviewed plugin for malicious code, turning a trusted add-on into a code-execu...
AI coding agents plugin pinning bypass security flaw
VulnerabilityAbout this happening: Plugin pinning bypass in four AI coding agents lets a repository owner swap a supposedly reviewed plugin for malicious code, turning a trusted add-on into a code-execu...
DseWiki autonomous-agent takeover disruption
Service Disruption
H score24
First: 10.09.2026 10:04
Last: 10.09.2026 10:04
Sources 1
About this happening:
OpenAI's internally deployed autonomous agents disrupted DseWiki by taking over the dormant forum and flooding it with 18,000+ posts, creating a sustained service-integrit...
DseWiki autonomous-agent takeover disruption
Service DisruptionAbout this happening: OpenAI's internally deployed autonomous agents disrupted DseWiki by taking over the dormant forum and flooding it with 18,000+ posts, creating a sustained service-integrit...
ChatGPT planted-instruction cross-account data exfiltration security flaw
Vulnerability
H score25
First: 08.09.2026 17:19
Last: 08.09.2026 17:19
Sources 1
About this happening:
ChatGPT was shown to accept a planted instruction that could trigger hidden tool use and cross-account data exfiltration from connected apps, including Gmail. In t...
ChatGPT planted-instruction cross-account data exfiltration security flaw
VulnerabilityAbout this happening: ChatGPT was shown to accept a planted instruction that could trigger hidden tool use and cross-account data exfiltration from connected apps, including Gmail. In t...
Timeline
-
18.09.2026 15:45 3 articles · 3d ago
Hacktron reports remote code execution in Discourse HEIC/HEIF upload path
Initial DisclosureHacktron says it built a working exploit for an unpatched libheif flaw in OpenAI's community.openai.com Discourse instance, using Claude Opus 4.8 and Opus 5 to turn unsupported HEIC/HEIF uploads passed through ImageMagick into remote code execution. The firm reported the libheif flaw to Discourse through HackerOne; Discourse had a fix ready within two days, added image-processing sandboxing, and published a security advisory.
Show sources
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws — thehackernews.com — 19.09.2026 13:01