{
  "id": 8348468,
  "title": "Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain",
  "url": "https://urgent.news/2026/09/19/reaching-an-internal-openai-repository-through-an-heif-rce-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-19T00:56:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/reaching-an-internal-openai-repository-through-an-heif-rce-and-overprivileged-sso-token-chain-26d8"
  },
  "original_language": "en",
  "account": "OpenAI's internal repository was compromised through a complex attack chain. Researchers initially exploited a heap overflow vulnerability in the libheif library used by Discourse's HEIF image decoder. This allowed them to execute arbitrary code (RCE) and acquire an overprivileged Single Sign-On (SSO) token within the OpenAI forum environment.\n\nWith the overprivileged SSO token, the attackers accessed an employee's ChatGPT/Codex account. Using the employee account connected to GitHub via ChatGPT/Codex, the attackers created a harmless pull request in the internal repository as a proof-of-concept demonstration. This showed how the attackers could potentially access and manipulate the organization's internal codebase.\n\nThe vulnerability chain began with the RCE in Discourse's image-processing environment due to a crafted HEIF image. The HEIF image was passed through ImageMagick to the vulnerable libheif library version 1.19.7, which resulted in the heap overflow and RCE. The researchers then leveraged the overprivileged OpenAI SSO token to gain access to the employee's ChatGPT/Codex account. This allowed them to create a pull request in the internal repository through Codex's GitHub connection.\n\nWhile the researchers were able to read metadata and commit the internal GitHub repository and create a pull request for the repository's README, they did not confirm actual access to Slack messages. OpenAI confirmed that Slack messages were not accessed as part of the attack. The success conditions for the attack included a vulnerable Discourse environment, an overprivileged OpenAI SSO token, and a connected GitHub account to the ChatGPT/Codex service.\n\nTo mitigate the risk, OpenAI advised rebuilding the Discourse Docker image and applying a patched libheif library. They also recommended limiting SSO token scopes and revoking existing tokens and sessions. Monitoring for email notifications related to account changes, as well as proxy, SWG, and DNS logs for abnormal image uploads and communication, can help detect potential compromises.",
  "summary": "1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity Basis: Researchers achieved RCE on OpenAI Forums via a heap overflow in the HEIF image decoder, chained an over-privileged SSO token, and created a pull request in the internal repository via the employee's ChatGPT/Codex account and connected GitHub.…",
  "key_points": [
    "Attackers exploited heap overflow in libheif library to execute arbitrary code (RCE)",
    "Overprivileged SSO token allowed access to ChatGPT/Codex employee account",
    "Attackers created proof-of-concept pull request in internal OpenAI repository"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}