{"id":266,"date":"2026-09-29T20:23:32","date_gmt":"2026-09-29T20:23:32","guid":{"rendered":"https:\/\/managedt.com\/blog\/chained-forum-sso-flaws-exposed-chatgpt-codex-accounts\/"},"modified":"2026-10-09T02:58:50","modified_gmt":"2026-10-09T02:58:50","slug":"chained-forum-sso-flaws-exposed-chatgpt-codex-accounts","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/chained-forum-sso-flaws-exposed-chatgpt-codex-accounts\/","title":{"rendered":"Chained Forum and SSO Flaws Exposed ChatGPT and Codex Accounts"},"content":{"rendered":"<p>Two vulnerabilities, one in an image decoder used by the OpenAI help forum and one in the sign-in flow that links that forum to ChatGPT and Codex, were chained together in late July 2026 to take over employee accounts. Because Codex can be connected to services such as GitHub, the same chain opened a path to internal OpenAI code, and the finding was demonstrated with a benign pull request opened from a compromised employee account before testing was stopped.<\/p>\n<h2>What the chain looked like<\/h2>\n<p>The forum at community.openai.com runs on Discourse and allows sign-in with OpenAI accounts through auth.openai.com. That link from a forum session to an OpenAI identity was the second half of the chain. The first half was an image upload. Discourse normally uses FastImage to inspect images, but HEIC, HEIF, and AVIF files are passed to ImageMagick&#8217;s <code>magick<\/code> command for conversion, which calls libheif directly on attacker-controlled files.<\/p>\n<p>The Debian 12 base image used by Discourse shipped libheif 1.19.7. Debian 13 shipped 1.19.8. Both carried a heap buffer overflow that had been fixed upstream but was not marked as a security fix and received no CVE, so it was not backported. As of September 14, 2026, the latest upstream security release is libheif v1.23.4; v1.23.2 has been superseded by further security fixes. Debian published its security update for Debian 13 on August 8, 2026.<\/p>\n<p>Anthropic&#8217;s Claude Opus 4.8 was used to review the installed libheif package and locate the missing backport, then to build an exploit with ASLR disabled. Anthropic released Claude Opus 5 that evening. The newer model produced a working ARM64 exploit for a local Mac within three hours, then ported it to the x86-64 and jemalloc configuration used by Discourse. By 6:00 a.m. UTC on July 25, 2026, local remote code execution through an image upload had been confirmed.<\/p>\n<p>The exploit was then run in an autonomous goal loop against a Discourse Cloud instance, reached remote code execution there, and was finally aimed at OpenAI&#8217;s own forum. No user interaction was needed once the crafted image was uploaded.<\/p>\n<h2>From forum admin to ChatGPT and Codex<\/h2>\n<p>Administrative access to community.openai.com was enough because of how sign-in worked. The OpenAI SSO flow that backed the forum&#8217;s &#8220;Sign in with OpenAI&#8221; option carried the same trust into ChatGPT and Codex, so a forum compromise mapped onto a ChatGPT and Codex compromise without a password prompt. Any first-party or third-party OpenAI service using that SSO would have inherited the same exposure; the forum was just one way to prove it.<\/p>\n<p>Connected integrations widened what a taken-over account could reach. With Codex linked to GitHub, the same account could open pull requests inside OpenAI&#8217;s internal monorepo. To show the path without reading any internal code, a prompt was sent to the compromised Codex account asking it to open PR #1186742 in openai\/openai, a benign change. Testing stopped after that.<\/p>\n<h2>Timeline of the disclosure<\/h2>\n<ul>\n<li>July 25, 2026, 05:00 to 06:00 UTC: Initial finding. Remote code execution and administrative access were obtained on the Discourse environment at community.openai.com.<\/li>\n<li>July 25, 2026, 08:00 to 10:00 UTC: Report submitted through OpenAI&#8217;s Bug Bounty Program on Bugcrowd after cross-product impact was confirmed.<\/li>\n<li>July 25, 2026, 13:30 to 15:30 UTC: Proof of concept. The benign pull request was opened in OpenAI&#8217;s internal monorepo, the Bugcrowd report was updated with impact details, and all further testing was stopped.<\/li>\n<li>July 25, 2026, 22:49:45 UTC: OpenAI confirmed the issue had been fixed, roughly 14 hours after the initial submission.<\/li>\n<li>July 25, 2026: Discourse was notified through its HackerOne program.<\/li>\n<li>July 26, 2026: Discourse responded.<\/li>\n<li>July 27, 2026: Discourse had a fix ready and added image-processing sandboxing as defense in depth.<\/li>\n<li>July 28, 2026: Discourse published advisory GHSA-vhm9-85gw-x335 with patch and rebuild guidance.<\/li>\n<li>September 1, 2026: OpenAI paid a $6,500 bounty and marked the report resolved. OpenAI noted that testing against community.openai.com was excluded from its bug bounty scope, and that the award recognized the OpenAI-side finding, not the actions against Discourse.<\/li>\n<\/ul>\n<h2>Who else was affected<\/h2>\n<p>The libheif issue is not specific to Discourse or OpenAI. The same research has been expanded into a multi-month investigation labeled HEIF Heist, tracing libheif through Slack, Meta, GitHub Enterprise, Ruby on Rails, and Node.js frameworks including Next.js, Astro, and Gatsby. Any application that processes user-controlled images and accepts .heic, .heif, or .avif files is likely affected if it is running an unpatched libheif or libde265.<\/p>\n<p>Adapting the exploit to each new target usually took one to two days, and the total token spend across the broader two-month project was less than $3,000. Across the campaign, no company other than Shopify was observed detecting the activity, even after thousands of images were uploaded and image processors repeatedly crashed.<\/p>\n<h2>What defenders should do now<\/h2>\n<p>The standard upgrade advice is the only safe starting point. Install the latest security-patched libheif and libde265 packages through the distribution&#8217;s security channel, or move to the current upstream release. Because distribution packages often carry backports under an older upstream version number, the package security advisory matters as much as the version string. The ISO base media file format is complex and decoder updates are frequent, so future memory-safety flaws are likely. Disable untrusted HEIF and AVIF decoding where it is not needed, or isolate image-processing pipelines inside hardened, ephemeral sandboxes. ImageMagick&#8217;s security policy can restrict accepted formats and resource use.<\/p>\n<p>Self-hosted Discourse operators should rebuild the container, not just update through the admin interface. Running <code>git pull<\/code> and <code>.\/launcher rebuild app<\/code> from <code>\/var\/discourse<\/code> replaces the base image, while a web update alone may leave the vulnerable libheif dependency in place. Discourse-hosted customers have already been patched.<\/p>\n<h2>What the broader result implies<\/h2>\n<p>Memory-corruption bugs used to require specialized expertise, considerable time, and detailed knowledge of the target environment. Known issues were costly to weaponize, so ordinary companies had practical protection even when vulnerable code and flaws were public. That protection is collapsing as memory-corruption exploits now take only hours of compute to build.<\/p>\n<p>A realistic threat model should account for the economics of exploitation now, not the economics of exploitation a few years ago. A small team can use general-purpose models to turn a memory-corruption bug into a working exploit against an unfamiliar environment, including privilege escalation and lateral movement when code execution lands inside a restricted sandbox. Skilled human guidance still matters, but the volume of work a small team can perform has increased sharply.<\/p>\n<h2>FAQ<\/h2>\n<h3>What was the root cause of the ChatGPT and Codex account takeover?<\/h3>\n<p>A heap buffer overflow in libheif, exposed through Discourse&#8217;s image-upload pipeline when HEIC, HEIF, or AVIF files were handed to ImageMagick, gave remote code execution on the forum at community.openai.com. An OpenAI SSO misconfiguration then carried that forum session into ChatGPT and Codex without a password prompt.<\/p>\n<h3>What versions of libheif are affected?<\/h3>\n<p>Any deployment missing the latest upstream security patches is potentially affected, across multiple release families including 1.19.x, 1.20.x, 1.22.x, and 1.23.x. As of September 14, 2026, the latest upstream libheif security release is v1.23.4, and v1.23.2 has been superseded by further security fixes.<\/p>\n<h3>How long did the full exploit chain take, and what did it cost?<\/h3>\n<p>The full chain from initial discovery on July 23, 2026 to the benign pull request opened on July 25, 2026 took less than 72 hours. The broader two-month HEIF Heist campaign across Slack, Meta, GitHub Enterprise, and other targets cost less than $3,000 in tokens and was conducted by three researchers.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What was the root cause of the ChatGPT and Codex account takeover?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A heap buffer overflow in libheif, exposed through Discourse's image-upload pipeline when HEIC, HEIF, or AVIF files were handed to ImageMagick, gave remote code execution on the forum at community.openai.com. An OpenAI SSO misconfiguration then carried that forum session into ChatGPT and Codex without a password prompt.\"}},{\"@type\":\"Question\",\"name\":\"What versions of libheif are affected?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Any deployment missing the latest upstream security patches is potentially affected, across multiple release families including 1.19.x, 1.20.x, 1.22.x, and 1.23.x. As of September 14, 2026, the latest upstream libheif security release is v1.23.4, and v1.23.2 has been superseded by further security fixes.\"}},{\"@type\":\"Question\",\"name\":\"How long did the full exploit chain take, and what did it cost?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The full chain from initial discovery on July 23, 2026 to the benign pull request opened on July 25, 2026 took less than 72 hours. The broader two-month HEIF Heist campaign across Slack, Meta, GitHub Enterprise, and other targets cost less than $3,000 in tokens and was conducted by three researchers.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.hacktron.ai\/blog\/hacking-openai\" target=\"_blank\" rel=\"nofollow noopener\">hacktron.ai<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A forum image-upload flaw and an SSO misconfiguration were chained to take over ChatGPT and Codex accounts, including connected GitHub access.<\/p>\n","protected":false},"author":3,"featured_media":265,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-266","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/266","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=266"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/266\/revisions"}],"predecessor-version":[{"id":511,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/266\/revisions\/511"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/265"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=266"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=266"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=266"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}