In July 2026, security researchers at Hacktron AI successfully exploited two critical vulnerabilities to gain unauthorized access to OpenAI employees' ChatGPT and Codex accounts. The researchers utilized Anthropic's Claude models to develop and port exploits, ultimately gaining remote code execution (RCE) via a vulnerability in the Discourse forum used by the OpenAI Developer Community.
Researchers use Anthropic's Claude to exploit Discourse vulnerability and access OpenAI internal data
The attack leveraged a vulnerability in the libheif package used during image processing. When the Discourse forum processed HEIC/HEIF files, it passed them to the ImageMagick command for conversion, exposing the vulnerable libheif library. The researchers used Claude Opus 4.8 to identify the unpatched security issue in the library and later used Claude Opus 5 to port the exploit to the specific x86-64 environment used by Discourse.
By compromising a forum account, the researchers were able to exploit OpenAI's Single Sign-On (SSO) configuration, which facilitated access to broader services. To prove the impact without accessing sensitive data, the team used a compromised Codex account to open a harmless pull request in OpenAI’s internal monorepo.
OpenAI has since patched the vulnerability and awarded Hacktron AI a $6,500 bounty through its Bug Bounty program. Hacktron AI noted that the exploitation process, which traditionally requires significant human expertise and time, was dramatically accelerated by using AI agents.
Sources
- ハッカーがAnthropicのClaudeを使ってOpenAIに侵入 (GIGAZINE, 2026-09-19)
- Hacktron AI