The forum runs Discourse, the off-the-shelf software behind countless community sites. Discourse was still shipping an old copy of libheif, the library that decodes iPhone-style photos. The bug in it had already been fixed upstream.
But the fix was never labelled a security fix, so nobody treated it as urgent.
Hacktron's researchers uploaded a HEIF image and got their own code running on community[.]openai[.]com.
Then came the second bug, in OpenAI's own single sign-on, the "log in with OpenAI" button the forum uses. It turned that forum foothold into the actual ChatGPT and Codex accounts of people who had signed in there. OpenAI employees among them.
And a ChatGPT account is no longer just a chatbot. Through Codex, users wire in Gmail, Outlook, Drive, Slack, GitHub.
To prove the access was real, they used one employee account to have Codex open a harmless pull request in OpenAI's internal repo. They say they read no sensitive code.
OpenAI patched the SSO flaw roughly 14 hours after the report and paid a $6,500 bug bounty.
The team says Anthropic's Opus 4.8 found the libheif bug, and Opus 5 turned it into a working exploit.
Slack, Meta, GitHub Ent, Rails, Next.js, ImageMagick, and many more were also vulnerable and compromised by the same team of researchers.
