One write past the chunk, read-write on the repo
On July 25, 2026, a team at Hacktron used an OpenAI employee's Codex to open pull request #1186742 in openai/openai , OpenAI's internal monorepo. They got there by chaining a heap buffer overflow in libheif with an SSO misconfiguration in OpenAI's identity infrastructure. The path from first looking at the forum's image pipeline to repo access took under 72 hours. OpenAI paid a $6,500 bounty. How…
On July 25, 2026, a team at Hacktron exploited a heap buffer overflow in libheif and an SSO misconfiguration in OpenAI's identity infrastructure to gain repo access in openai/openai, OpenAI's internal monorepo. This path took under 72 hours, and OpenAI paid a $6,500 bounty. The forum was used to demonstrate the attack, as it operates on Discourse, which hands .heic/.heif files to ImageMagick's magick command for conversion, putting attacker-controlled files straight into the libheif parser.
A heap buffer overflow during HEIC decoding provided out-of-bounds read and write primitives. The fix for the underlying bug had already been upstream, but it was not labeled as a security fix and received no CVE, which likely prevented Debian from implementing it in time. The escalation's significance lies in the fact that OpenAI offers "Sign in with OpenAI" through auth.openai.com, allowing no-interaction takeover of ChatGPT and Codex accounts of active forum members when combined with the SSO misconfiguration.
Hacktron's memory-corruption work turned out to be crucial, as Opus 4.8 initially produced a working ImageMagick/libheif exploit with ASLR disabled, but Opus 5, released by Anthropic, generated a reliable ARM64 exploit for a local Mac within three hours and then ported it to x86-64 and jemalloc setup Discourse uses. By 6:00 a.m. on July 25, Hacktron confirmed local RCE through an image upload.
They then used an autonomous /goal loop against their own Discourse Cloud instance, proving RCE on Discourse Cloud by reading /etc/hosts. The same script worked against OpenAI's instance, allowing the team to take over an employee account connected to OpenAI's GitHub organization, prompting that Codex to open the proof-of-concept PR, and then stopping.
OpenAI acknowledged the fix within 14 hours, and Discourse fixed the issue separately through HackerOne within 24 hours, adding ImageMagick sandboxing as defense in depth.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.