AI-Generated Exploit and Token Flaw Breached OpenAI Internal
Researchers used an AI model to build an exploit for an unpatched library flaw, chaining it with an OpenAI sign-in token vulnerability to access internal

Security researchers at Hacktron used Anthropic's Claude AI to build a working exploit for an unpatched vulnerability in an image-processing library. They then chained this with a flaw in OpenAI's sign-in system to take over employee accounts and gain access to internal code repositories.
The attack began on OpenAI's community forum, which runs on the Discourse platform. Because Discourse's built-in image checks do not support the HEIC/HEIF photo format, uploads in that format were passed to the ImageMagick tool for processing. This exposed a vulnerability in the libheif library that ImageMagick uses for decoding.
Hacktron states the underlying bug in libheif had been fixed upstream a year earlier. However, it was never flagged as a security issue, was never assigned a CVE identifier, and was missed in standard patching cycles.
Building the Exploit with AI
Creating a reliable exploit from this flaw required several attempts and involved using Claude Opus 4.8 and Opus 5 models. The resulting exploit allowed for remote code execution. The researchers first tested it against a Discourse instance they controlled, then successfully deployed it on OpenAI's own community forum.
Because the forum allowed users to sign in with their OpenAI account, executing code on the forum server opened a path to broader account compromise. Hacktron claims that until the issue was fixed, any user or employee who logged into the forum could have had their associated ChatGPT and Codex accounts taken over.
The Account Takeover Path
OpenAI distinguishes the two flaws involved. The company told SecurityWeek that the image-processing bug existed in the third-party Discourse service. The account-takeover path, however, was a separate issue on OpenAI's side.
The OpenAI-specific weakness involved sign-in tokens generated for the community forum. These tokens carried excessive permissions, granting full API access to the associated ChatGPT and Codex accounts. Since people often connect other services to these accounts, the theoretical exposure extended to linked platforms like GitHub, Slack, and email.
To demonstrate the level of access without reading internal code, Hacktron says it took over an OpenAI employee's account. This account's Codex integration was linked to OpenAI's GitHub organization. Using this access, the researchers opened a pull request in an internal repository before halting further testing.
OpenAI's own review of the incident found limited reads of private-repository metadata and commits, followed by the researcher-submitted pull request to a README file. Hacktron's report also raises Slack as a service that could theoretically have been reached. OpenAI states Hacktron did not verify actual access to employee Slack messages.
Vendor Response and Patches
Hacktron reported the account-takeover issue to OpenAI through the Bugcrowd platform. OpenAI confirmed a fix approximately 14 hours later. The security firm separately reported the libheif flaw to Discourse through HackerOne. Discourse had a fix ready within two days and added image-processing sandboxing as an extra defensive layer before publishing a security advisory.
In a statement, OpenAI said, "We thank the researchers for contacting us and sharing their findings." The company paid Hacktron a $6,500 bounty for the OpenAI-side finding.
OpenAI has previously stated its models searched GitHub for leaked API keys during training. Other recent research has shown AI agents can retrain their own models mid-task, potentially leaking secrets. The company is also investigating a report linking AI agents to a RubyGems attack.





