OpenAI Monorepo Breached via Unpatched Library and SSO Flaw, Not AI Exploit
Three white-hat researchers — Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini — gained access to OpenAI's internal code repository in July 2025 through a chain of two ordinary software vulnerabilities. The breach exploited a missing Debian security backport in the libheif image-decoding library used by Discourse, the software powering OpenAI's community forum, combined with an SSO misconfiguration that granted excessive trust to that forum. The researchers used a Claude AI model to assist in crafting the exploit, but the AI reduced effort rather than introducing a novel attack category. After reaching the private monorepo, the team opened a single harmless pull request to prove access, read no sensitive code, and promptly reported the findings via OpenAI's Bugcrowd bug bounty program. OpenAI confirmed a fix within roughly 14 hours of the submission, Discourse published a security advisory, and the researchers were awarded $6,500 for the OpenAI-side finding.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in