Skip to content
Hacktron Exploits OpenAI GitHub via HEIF Vulnerability

Hacktron Exploits OpenAI GitHub via HEIF Vulnerability

First seen 22 Sep 2026, 08:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 09:53 UTC
  • Hacktron exploited a zero-day in libheif to access OpenAI's GitHub.
  • The attack involved a malicious HEIF image uploaded to OpenAI's forum.
  • CVE-2026-32882 is rated 8.8 under CVSS and has been patched.

Hacktron researchers exploited a zero-day flaw in libheif to access OpenAI's internal GitHub repository. The attack began with a malicious HEIF image uploaded to OpenAI's Discourse forum, which allowed them to bypass the identity layer and access an employee's Codex account. They subsequently opened a benign pull request in OpenAI's private monorepo to demonstrate their access. The vulnerability, tracked as CVE-2026-32882, was rated 8.8 under CVSS and required low privileges for exploitation. OpenAI fixed the identity flaw within 14 hours of its discovery in July and awarded Hacktron a $6,500 bounty. Security experts have raised concerns about the ethics of Hacktron's approach, as it mirrored actions a malicious actor might take. The incident highlights the need for improved security measures in organizations handling sensitive data.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-19
CVE-2026-32882 published
A vulnerability in libheif was disclosed, affecting systems using this image decoder.
Esecurityplanet
2026-07-25
OpenAI forum compromised
Hacktron exploited a flaw in OpenAI's Discourse forum to gain unauthorized access.
Esecurityplanet
2026-09-13
Hacktron details attack chain
Hacktron published the full attack chain, revealing how they accessed OpenAI's GitHub.
Esecurityplanet
2026-09-15
Discourse patched vulnerability
Discourse updated its base image to include a security fix for libheif.
Esecurityplanet
2026-09-22
Hacktron's actions criticized
Security professionals expressed concerns over Hacktron's decision to open a pull request in OpenAI's GitHub.
Thestack.Technology

More articles in this cluster (3)

Following this threat?

Track OpenAI and CVE-2026-32882 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed