Researchers Breach OpenAI Internal Repo via HEIF Image Flaw and Overprivileged SSO Token
Security researchers disclosed a critical vulnerability chain, assigned CVE-2026-32882, that allowed remote code execution on OpenAI's Discourse-based forum by uploading a crafted HEIF image that exploited a heap overflow in libheif 1.19.7 via ImageMagick. The RCE enabled attackers to harvest an overprivileged OpenAI SSO token from the compromised forum environment, which was then used to access an employee's ChatGPT and Codex account. Through the employee account's connected GitHub integration, researchers demonstrated the impact by having Codex submit a pull request to an internal OpenAI repository. The exploit was developed with assistance from Claude Opus AI models, though the process required expert human guidance and was not fully autonomous. Recommended mitigations include patching libheif, sandboxing image processing, and restricting SSO token scopes to least-privilege principles.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in