Skip to content
Trending storyPast story

Three old authorizations, two days, into OpenAI's internal repo

1 report1 sourceupdated 4 days ago

What happened

Summary

安全团队 Hacktron 从 OpenAI 公开论坛的图片上传接口入手,利用 libheif 一个已知的内存漏洞拿到了论坛管理员权限。论坛登录直接挂在 OpenAI 的统一认证系统上,顺着这条信任链,他们接管了一名内部工程师的 ChatGPT 和 Codex 账户。这名工程师之前把个人 GitHub 授权给了 Codex,于是测试人员借 Codex ...

Coverage

Follow the reports to see the story from different sides.

Sep 25
  1. Computing Life · Share · YagePick
    Three old authorizations, two days, into OpenAI's internal repo

    Security team Hacktron exploited a known libheif memory bug via OpenAI's public forum image upload, gained forum admin, then pivoted through OpenAI's SSO to take over an internal engineer's ChatGPT and Codex accounts. The engineer had previously authorized Codex on their personal GitHub, allowing the team to create a branch and submit a pull request in the core openai/openai repo—no source code was read, no customer data touched. OpenAI fixed the issue ~14 hours after the report and paid a $6,500 bounty covering only the SSO finding; the forum itself was excluded from scope. The entire chain used existing configurations: the image parsing flaw stemmed from a libheif code change from a year earlier, still unpatched in Debian's old stable branch; trust propagation came from the forum unconditionally relying on centralized SSO; repo write access came from the engineer's routine Codex authorization. Claude Opus 5 helped compress exploit-writing from days to hours after humans had already pinpointed the root cause and set up the debugging environment—it did not autonomously discover the vulnerability.