Hacktron chained a libheif heap overflow through Discourse and an OpenAI SSO flaw into a PR on OpenAI's internal monorepo
Hacktron published its writeup on 2026-09-18 describing a chain from a heap buffer overflow in libheif 1.19.7/1.19.8 (a missing Debian 12/13 security backport) through ImageMagick's HEIF handling, into Discourse image uploads on community.openai.com, then via an OpenAI SSO identity misconfiguration into employee ChatGPT and Codex accounts, connected GitHub integrations, and finally OpenAI's internal repos, where they had an AI assistant open a proof-of-concept pull request in the monorepo. The timeline is tight: initial RCE and Discourse admin at 05:00-06:00 UTC on 2026-07-25, employee account access by 15:30, OpenAI confirming a fix at 22:49 the same day. OpenAI awarded $6,500 on 2026-09-01, explicitly for the SSO finding rather than the Discourse compromise. The lesson for builders is that a distro's missing backport in an image codec is now three hops from your agent's repo access.
Source
↳ Follow the thread