Urgent.News

What's breaking now, across thousands of outlets.

Tech

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity Basis: Researchers achieved RCE on OpenAI Forums via a heap overflow in the HEIF image decoder, chained an over-privileged SSO token, and created a pull request in the internal repository via the employee's ChatGPT/Codex account and connected GitHub.…

OpenAI's internal repository was compromised through a complex attack chain. Researchers initially exploited a heap overflow vulnerability in the libheif library used by Discourse's HEIF image decoder. This allowed them to execute arbitrary code (RCE) and acquire an overprivileged Single Sign-On (SSO) token within the OpenAI forum environment.

With the overprivileged SSO token, the attackers accessed an employee's ChatGPT/Codex account. Using the employee account connected to GitHub via ChatGPT/Codex, the attackers created a harmless pull request in the internal repository as a proof-of-concept demonstration. This showed how the attackers could potentially access and manipulate the organization's internal codebase.

The vulnerability chain began with the RCE in Discourse's image-processing environment due to a crafted HEIF image. The HEIF image was passed through ImageMagick to the vulnerable libheif library version 1.19.7, which resulted in the heap overflow and RCE. The researchers then leveraged the overprivileged OpenAI SSO token to gain access to the employee's ChatGPT/Codex account. This allowed them to create a pull request in the internal repository through Codex's GitHub connection.

While the researchers were able to read metadata and commit the internal GitHub repository and create a pull request for the repository's README, they did not confirm actual access to Slack messages. OpenAI confirmed that Slack messages were not accessed as part of the attack. The success conditions for the attack included a vulnerable Discourse environment, an overprivileged OpenAI SSO token, and a connected GitHub account to the ChatGPT/Codex service.

To mitigate the risk, OpenAI advised rebuilding the Discourse Docker image and applying a patched libheif library. They also recommended limiting SSO token scopes and revoking existing tokens and sessions. Monitoring for email notifications related to account changes, as well as proxy, SWG, and DNS logs for abnormal image uploads and communication, can help detect potential compromises.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos…

  • Signed kernel driver disables EDR by terminating antivirus processes
  • Fake GitHub repositories distribute malware via DLL side-loading
  • Malware steals data and transmits to command and control server

India forces caller-ID apps to feed spam reports to telcos

Truecaller says the one-way sharing requirement would hand a commercially valuable proprietary asset to telecom operators.

  • Indian government compels caller-ID apps to send spam reports to telecoms.
  • TRAI mandates apps to forward spam reports to blockchain platform managed by telecoms.
  • Truecaller criticizes move as anti-competitive, serving 350M+ Indian users.

More from Saturday 19 September →