Vulnerabilities & Exploits

OpenAI Forum Bug Bridged Into Staff Accounts

Hacktron used Claude Opus 5 to chain a Discourse upload flaw with an OpenAI login weakness and reach several employees’ ChatGPT and Codex accounts, then touch an internal code repository. OpenAI says it fixed the issue about 14 hours after the report and later paid the team a $6,500 bounty, which it said covered the OpenAI-side login finding rather than the forum bug itself.

The first bug was in Discourse’s HEIC/HEIF upload path, where ImageMagick handed a crafted image to libheif and a memory flaw turned into remote code execution, tracked as CVE-2026-32882. The second bug was the trust bridge: OpenAI’s public forum and employee tools reused the same sign-in path, so control of the forum side could spill into staff accounts without any employee action.

That leaves the important exposure at the identity layer, not just the forum host. If a public support portal shares SSO with internal SaaS, a bug in the front door can still become access to employee mail, chat, and code even after the visible app is patched.

7 sources · Sep 21

CVE-2026-32882

NVD KEV

CVSS 7.1 HIGH: libheif is a HEIF and AVIF file format decoder and encoder. EPSS 0.3% (27th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-09-18

Every edition of this story: OpenAI Forum Bug Bridged Into Staff Accounts

More from today