Researchers from Hacktron AI discovered a security vulnerability that allowed them to access OpenAI's internal GitHub repository. The exploit involved a chain of attacks starting with a heap overflow in the libheif library, which was triggered through the ImageMagick software used on OpenAI's Discourse community forum. Once inside, the researchers used a flaw in OpenAI's Single Sign-On (SSO) system to briefly take control of employee accounts for ChatGPT and Codex, two of OpenAI's AI tools. The team referenced XKCD #2347, a 2020 comic whose alt text humorously predicted that ImageMagick, a widely used image processing library, would one day cause major issues. This comic seemed oddly prescient in 2026, as ImageMagick turned out to be the key to accessing the deeper vulnerability.
The vulnerability stemmed from the way OpenAI's community forum, hosted on Discourse, used ImageMagick’s magick command to convert HEIF images. A specific version of ImageMagick, deployed through Debian, had a known heap buffer overflow issue that had been patched the previous year. However, it was not flagged as a potential security risk. Hacktron AI exploited this unpatched flaw and combined it with a secondary SSO misconfiguration, allowing them to gain access to ChatGPT and Codex accounts through the forum. The team then made a harmless pull request to OpenAI’s internal GitHub as a proof of concept before notifying the company.
OpenAI responded quickly, patching the issue within 14 hours and awarding Hacktron AI a $6,500 bug bounty. Discourse, the forum software used by OpenAI, also addressed the underlying image processing vulnerability, rating it 8.8 on the CVSS scale—a high severity score. They implemented sandboxing to isolate image processing tasks and reduce the risk of similar exploits. The vulnerability, however, is not unique to OpenAI. The same libheif and libde265 decoders are used in various other platforms and frameworks, including Slack, Meta, GitHub Enterprise, Ruby on Rails, and JavaScript-based tools like Next.js, Astro, and Gatsby. If unpatched, the potential impact could be widespread.
Hacktron AI's research process was remarkably efficient. Using Anthropic’s Claude Opus 4.8 and later Opus 5, the team spent less than $3,000 in AI tokens across a three-person team and developed a working exploit in just two months. They had to guide the AI by presenting their test forum as a "capture-the-flag" challenge, a common method in cybersecurity training, before the AI complied with their request. This case highlights both the speed at which vulnerabilities can be discovered and the importance of proactive security measures in widely used software components.
Hack Researchers Exploit ImageMagick Vulnerability to Access OpenAI Systems
AI-rewritten from original reportingHow it works
imagemagicksecuritybug-bountyopenailibheifsoftware-vulnerability



