Hacktron: Claude-built libheif RCE (CVE-2026-32882) + OpenAI SSO → employee ChatGPT/Codex + internal repos
Hacktron AI (Harsh Jaiswal, Mohan Pedhapati, Rahul Maini; blog 13 September 2026; SecurityWeek wire 18 September) chained a heap buffer overflow in Debian-packaged libheif (CVE-2026-32882 / Discourse GHSA-vhm9-85gw-x335) with an OpenAI SSO/sign-in flaw on community.openai.com (Discourse). Attackers uploaded a crafted HEIF via forum image upload for RCE on the Discourse host, then abused OpenAI “Sign in with OpenAI” identity flow to take over employee ChatGPT and Codex accounts (connectors can reach GitHub/Slack/email). Impact proof: prompted a compromised employee Codex to open PR #1186742 in OpenAI’s internal monorepo without reading secrets. Exploit development used Claude Opus models (Opus 4.8 struggled with ASLR; Opus 5 produced a working exploit within hours). Timeline: discovery to internal-repo access under 72 hours (July 2026); OpenAI confirmed fix ~14 hours after Bugcrowd report; Discourse patched and added ImageMagick sandboxing (self-host: git pull && ./launcher rebuild app — web UI update alone may leave vulnerable libheif). OpenAI paid $6,500 for the OpenAI-side finding (Discourse-hosted forum was out of bounty scope). Discourse GHSA rates CVSS 3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Broader HEIF Heist research notes the same libheif class across other image pipelines. Primary: Hacktron blog; also Discourse GHSA; wire: SecurityWeek 18 Sep.
- Product
- Discourse (community.openai.com and self-hosted) + OpenAI SSO / ChatGPT / Codex identity; Debian libheif via ImageMagick HEIF path
- Versions
- Vulnerable: Discourse Docker images shipping Debian libheif ~1.19.7 (Debian 12/13 missing security backport per Hacktron). Patched: latest Discourse Docker image with fixed libheif — rebuild via ./launcher rebuild app. OpenAI-hosted forum and SSO path fixed per vendor (~July 2026 response).
- CVSS
- (CVSS 3.1 High; Discourse GHSA for CVE-2026-32882)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Self-host Discourse: git pull && ./launcher rebuild app (not web-only update). OpenAI customers: no action — forum/SSO fixed. Review third-party HEIF/HEIC/AVIF image-upload pipelines using libheif.
Primary: Hacktron — Hacking OpenAI (libheif + SSO chain, 13 Sep 2026) · Vendor: Discourse GHSA-vhm9-85gw-x335 / CVE-2026-32882 (libheif via image upload) · CVE: CVE-2026-32882 · SecurityWeek — AI-built exploit + OpenAI sign-in flaw (18 Sep 2026)
