BlackTree Security · Infrastructure · Automation · AI

One Malformed Photo Put OpenAI’s Private Repository Within Reach

The first weakness was an image decoder. The final proof was a harmless pull request inside an OpenAI private repository. What connected those points was not one miraculous exploit but a sequence of trust decisions across a public forum, single sign-on, employee AI accounts and a linked GitHub organisation.

Hacktron researchers say they found the chain during responsible vulnerability research and reported it through OpenAI’s Bugcrowd channel. They uploaded a crafted HEIC image to OpenAI’s Discourse community forum. Because Discourse’s normal image check did not support the format, the file reached ImageMagick and an outdated libheif component. The researchers developed a working memory-corruption exploit and gained code execution on the forum environment.

The forum was only the first trust boundary

A forum compromise should not automatically become access to an employee’s ChatGPT or Codex account. The researchers report that OpenAI’s community sign-in flow issued tokens with excessive permissions. Combining the forum access with that identity weakness let them take over associated employee accounts.

One affected employee had connected Codex to OpenAI’s GitHub organisation. Hacktron says it used that access to create a harmless pull request in an internal repository. The team says it did not download source code and stopped once it had demonstrated impact.

This was responsible research rather than a malicious intrusion, and the proof action was deliberately limited. Hacktron says testing against the Discourse-hosted forum was explicitly outside OpenAI’s bug-bounty scope; OpenAI’s $6,500 reward covered the OpenAI-side sign-in finding. SecurityWeek reports that OpenAI fixed its issue in roughly 14 hours. The distinction between the third-party Discourse flaw and OpenAI’s own identity configuration is important: fixing the decoder did not remove the excessive sign-in authority, and correcting the sign-in path did not patch every other deployment of libheif.

Connected agents turn account scope into code scope

The chain illustrates why an AI account is no longer just a chat history. Coding agents can hold repository connections, delegated tokens and the ability to submit changes. A compromised identity may therefore inherit access that was granted for productivity but reaches into software supply chains.

  • Separate public-community identity. Do not let a lower-trust forum token inherit broad API access to employee AI or development services.
  • Inventory agent connections. Record which accounts can reach private repositories, cloud environments and build systems through AI tools.
  • Minimise delegated scopes. Prefer repository-specific, time-limited and task-limited permissions over organisation-wide access.
  • Patch processing chains. An application may call a vulnerable codec through ImageMagick or another wrapper even when the library is not visible in the product interface.
  • Review proof activity carefully. A harmless pull request can establish write capability, but it does not prove that source code was stolen.

The lesson is not that forums should never share identity with other services. It is that a community surface must not silently inherit the authority of an employee’s most powerful connected tools. Every hop in this chain worked because the next system trusted more than the previous one had earned.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *