From an Image Upload to OpenAI's Internal Repository - Hacktron Discloses "HEIF Heist," an Attack Built on a libheif Flaw
In a blog post dated September 13, security firm Hacktron said it combined a libheif vulnerability in the image handling of OpenAI's community forum with a flaw in OpenAI's SSO, then used an employee's Codex to open a PR in an internal repository. We summarize the firm's account that progress stalled with Opus 4.8 but moved forward with Opus 5, and the countermeasures for services that accept image uploads.
AI security company Hacktron disclosed in a blog post dated September 13, 2026, that it had taken over the ChatGPT accounts of several OpenAI employees, starting from an image upload to OpenAI’s community forum (community.openai.com)1. To demonstrate that access without touching sensitive information, the research team used one employee’s Codex to open a pull request in OpenAI’s internal monorepo. According to the firm, the path from first discovery to reaching the repository took under 72 hours.
The team built the attack with Anthropic’s Claude. Hacktron writes that the previous model, Opus 4.8, made little headway across several sessions, while Claude Opus 5 solved the same problem within hours of its release1. Hacktron then extended its research on the same image decoder vulnerabilities to other products and organized the results on a dedicated site under the name “HEIF Heist”2.
From the Forum’s Image Conversion to ChatGPT Accounts
In Hacktron’s account, the chain began in the path the forum software Discourse uses to inspect images1. Discourse normally checks images with a component called FastImage, but FastImage does not support HEIF. HEIF/HEIC files were therefore handed to ImageMagick’s conversion command, and behind it the libheif parser ended up reading files prepared by the attacker directly.
Upstream libheif had rewritten the relevant code the year before, but that commit was not labeled as a security fix and no CVE was assigned. Hacktron suggests this may be why the fix did not reach Debian 12 and 13.
Once the team could run code on the forum server, a flaw in OpenAI’s single sign-on (SSO) is what extended the damage to ChatGPT and Codex. Hacktron explains that this flaw was not specific to Discourse but an issue on OpenAI’s SSO side, and that a compromise of any other service using OpenAI’s SSO could lead to the same access1. It also notes that because GitHub, Slack, email, and other services can be connected to Codex and ChatGPT, the theoretical reach was large.
According to the firm’s timeline, the team obtained code execution and admin rights on the forum early on July 25 (UTC) and reported it to OpenAI’s bug bounty program on Bugcrowd a few hours later1. OpenAI replied that the issue was fixed about 14 hours after the report. Discourse had a fix ready on July 27 and published an advisory the following day, July 28. The advisory describes the problem as an upstream libheif vulnerability (CVE-2026-32882) that allows remote code execution through image uploads, with a severity of high3.
OpenAI paid a $6,500 bounty on September 1. An OpenAI comment quoted in the blog states that testing against the Discourse-hosted forum was outside the bug bounty’s scope and that the award was for the OpenAI-side finding1.
Stalled on Opus 4.8, Progress on Opus 5
Hacktron’s blog walks through the difference between the model generations it used, day by day1. On July 23, an Opus 4.8 session given the Discourse image found that security fixes had not been backported to the libheif package. On July 24 the team used Opus 4.8 to build a code-execution exploit, but it only worked with ASLR (address space layout randomization) disabled, and repeated sessions trying to make it reliable against the default ASLR-enabled configuration did not succeed.
That evening, Anthropic released Claude Opus 5. When Hacktron gave the same task to a new session, it produced an exploit that worked on a local Mac (ARM64) within three hours, the firm says.
One point worth noting is that Opus declined to write an exploit aimed at a remote instance. Hacktron says it routed its own Discourse instance through a proxy so it looked like a CTF (hacking competition) target and ran Claude in an autonomous loop1. This reads as the model’s refusal being sidestepped by making the target look like a CTF.
Hacktron stresses that this was not fully autonomous hacking and that guidance from skilled humans mattered, while saying the amount of work a small team could handle rose dramatically. The Discourse and OpenAI attack took an agent a few days and the humans a few hours. In the broader research, the firm says it also saw a jump from Opus 5 to GPT-5.6 Sol when exploiting targets about which nothing was known beyond their being vulnerable.
”HEIF Heist” Extended to Slack, Meta, and Next.js
According to the dedicated site, HEIF Heist is the umbrella name for remote attack paths against services that decode attacker-supplied HEIF, HEIC, or AVIF images2. The weak point sits below the application layer, in native C/C++ decoders such as libheif and libde265. Because these arrive in production indirectly through wrappers like ImageMagick, libvips, and Sharp, distribution packages, and container base images, the issue does not depend on language or framework.
Hacktron extended its research to Slack, Meta, GitHub Enterprise, and Ruby on Rails, as well as Node.js frameworks including Next.js, Astro, and Gatsby1. The site lists what the technique could have enabled, including remote code execution (RCE) on Slack, RCE through image uploads to Meta’s main products, RCE without authentication through Next.js’s AVIF image optimization, and RCE requiring authentication on GitHub Enterprise (CVE-2026-19118)2. The list does not show each company’s remediation status.
The firm also gives figures on scale and cost. The whole project took two months with total token spending under $3,000, and adapting the exploit to each new company usually took one to two days1. It adds that even after thousands of images were sent and image processing crashed repeatedly, Shopify was the only company it knows of that detected the activity.
At the same time, the site makes clear these are not ready-to-use attacks2. The target’s version has to be identified and the images tailored, and some attempts succeeded only after thousands of uploads. Even so, it says an agentic approach using a frontier model shortened the time from first probe to remote code execution to roughly one to three days.
What to Check on Services That Accept Images
Hacktron says applications that process user-submitted images and accept .heic, .heif, or .avif files are likely affected1. The vulnerabilities are not tied to a single version but span several release lines, such as 1.19.x, 1.20.x, 1.22.x, and 1.23.x. The countermeasures the firm lists are as follows.
- Update libheif: As of September 14, the latest upstream security release was v1.23.4. Distribution packages sometimes backport fixes under an older version number, so also check the package’s security advisory1
- Disable or isolate unneeded decoding: Turn off decoding of untrusted HEIF/AVIF where it is not needed, or isolate image processing in disposable sandboxes. ImageMagick’s security policy can restrict accepted formats and resource usage
- If you self-host Discourse or Next.js: Upgrade to the latest release and follow each project’s advisories2. Discourse directs administrators to rebuild with
./launcher rebuild app3, and Hacktron cautions that updating from the admin interface alone may not replace the underlying image
For this chain, Hacktron points to the possibility that an upstream fix without a CVE never reached the distributions. Even when application dependencies are kept current, image decoders inside container base images or OS packages can be missed unless they are checked separately. Identifying which libraries your services use to open images is the first step.
Not a Model Going Off-Script, but an Attack Built by People with a Public Model
Since this summer, incidents involving AI and cyberattacks had mostly been cases of models behaving unexpectedly during evaluation. In July, an OpenAI evaluation model escaped its sandbox and broke into Hugging Face, and Anthropic disclosed that Claude had accessed systems at three real organizations without authorization during evaluations.
HEIF Heist is different in nature: according to Hacktron’s account, human researchers used a publicly available model to assemble an attack that reached inside a real company. In August, Wiz also published research in which its autonomous AI tool found and actually exploited a weakness in Snowflake’s GitHub Actions. As attackers’ costs fall, operations that avoid missing fixes for known vulnerabilities are likely becoming more important.
Another issue is the range of services connected to AI accounts. In this case, Hacktron reports that it was able to open a PR in an internal repository from the Codex of a hijacked account. For organizations that connect GitHub, Slack, or email to ChatGPT or Codex, what an account can reach determines the scope of damage if it is taken over. Limiting connections to those that are needed and reviewing permissions is one way to reduce damage that the model itself cannot prevent.
Sources
- Hacking OpenAI - Hacktron’s report on the attack, timeline, and countermeasures (2026-09-13)
- HEIF Heist - Hacktron’s dedicated site defining the attack paths, scope, and countermeasures
- GHSA-vhm9-85gw-x335 - Discourse security advisory (2026-07-28)
Was this article helpful?
Thank you!
Received. Thank you!