Development · Articlepublished 6d
Hacktron chains Discourse RCE and OpenAI SSO flaw to reach internal repositories
Hacktron researchers say they chained a libheif remote-code-execution flaw in OpenAI's Discourse forum with an OpenAI SSO weakness to take over employee ChatGPT and Codex accounts and prove internal GitHub access through a harmless Codex-created pull request. OpenAI fixed its side the same day and later paid a $6,500 bounty; Discourse patched the RCE as CVE-2026-32882.
Hacktron AI - Hacking OpenAI · Discourse - RCE via malformed HEIF file