Hacktron reported chaining remote code execution in OpenAI’s community Discourse forum with an OpenAI single-sign-on identity flaw to take over ChatGPT and Codex accounts belonging to active forum users, including employees. The RCE reportedly stemmed from processing attacker-controlled HEIC/HEIF uploads through ImageMagick and a vulnerable libheif package in a Debian-based Discourse image; Hacktron demonstrated access by causing an employee-connected Codex account to open pull request #1186742 in OpenAI’s internal openai/openai monorepo, without accessing internal source code.
OpenAI and Discourse reportedly coordinated remediation: Discourse patched its hosted service and began sandboxing ImageMagick, while OpenAI awarded Hacktron a $6,500 bounty. Organizations processing untrusted HEIF or AVIF images should update libheif and libde265 promptly and isolate image-processing workloads, as similarly outdated deployments may remain exposed.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Debian published a security update for libheif on Debian 13, addressing the vulnerable package family identified in Hacktron's HEIF image-processing research.
Discourse published advisory GHSA-vhm9-85gw-x335 after receiving Hacktron's HackerOne report, documenting the libheif-related image-processing vulnerability affecting Discourse deployments.
OpenAI confirmed it fixed the OpenAI-side portion of the forum RCE and SSO account-takeover chain at 22:49:45 UTC on July 25, 2026, roughly 14 hours after Hacktron reported the issue.
Hacktron stated that on July 25, 2026, it chained an HEIC/HEIF image-processing RCE in OpenAI's Discourse forum with an OpenAI SSO identity flaw, compromising multiple OpenAI employees' ChatGPT accounts. The chain could allow takeover of active forum users' ChatGPT and Codex accounts without user interaction.
OpenAI reportedly awarded Hacktron a $6,500 bug bounty for its disclosure of the exploit chain and account-takeover impact.
Discourse reportedly received the report on a Saturday, responded on Sunday, and deployed a fix by Monday. Hosted customers were patched, while self-hosted operators were advised to rebuild installations because older Docker images could retain the vulnerable libheif dependency.
Hacktron stated that it promptly reported the initial vulnerability and account-takeover impact to OpenAI, and reported the Discourse issue through Discourse's HackerOne program.
Hacktron reported taking over an OpenAI employee account with a Codex instance connected to OpenAI's GitHub organization and creating pull request #1186742 in the internal openai/openai monorepo. It stated that it did not read internal source code during the demonstration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcehacktron.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.