🔥 Trending on HN

How an image upload reportedly reached internal repositories at OpenAI, the company behind ChatGPT

2 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
SSO

A login system that works across several services.

libheif

A software component that reads some image formats.

CVE-2026-32882

A public identifier for a specific security issue.

On July 25, 2026, a security report described a route from an image upload toward OpenAI’s internal repositories. It did not announce a mass source-code leak. It described a test of how several services could be chained.

What happened

On September 13, Hacktron AI’s report said its researchers linked two issues on July 25. First, they used an image upload on OpenAI’s community forum. They say a problem in image processing let the forum computer perform unintended actions. Second, they found an SSO configuration connecting the forum’s login with OpenAI accounts. The researchers say this combination reached employees’ ChatGPT and Codex accounts, then a GitHub-connected internal repository. They created a harmless pull request to demonstrate access, then stopped. They say they did not read sensitive information.

The background

The forum runs on Discourse, software for online communities. Some image uploads pass through ImageMagick and libheif. The official Discourse security advisory later described a high-severity issue involving malformed HEIF images. It assigned CVE-2026-32882 and listed patched Discourse versions. It also described extra sandboxing for image processing. This article does not need the exploit details. The larger point is that an ordinary upload feature depended on a lower-level image component.

SSO means single sign-on. One login can identify a person across several services. That can reduce friction. It can also make a mistake in one identity boundary matter elsewhere.

Why it matters

The reported chain crossed several trust boundaries: image upload, image conversion, forum login, OpenAI identity, and an external code integration. Each piece may look ordinary. Together, they created a path with much greater reach. The researchers also say they used AI models during parts of the investigation. That is their account, not an independent measurement. It does not prove every attack is now easy. It does suggest that defenders must consider faster, AI-assisted testing and isolate risky services.

What is confirmed

Hacktron AI says OpenAI confirmed its side was fixed about 14 hours after the first report. The report also says OpenAI paid a $6,500 bounty on September 1. Discourse published the advisory and patches. The supplied cluster records 478 points and 202 comments for the Hacker News post. That number shows community attention. It does not establish that the original report is correct. The Hacker News thread is therefore evidence of attention, not proof of the incident.

What remains unknown

Public material does not establish how many accounts were actually reachable, whether any sensitive data was viewed, or how far the connected services could be used. The proof pull request was redacted. The researchers say they stopped after the harmless demonstration. So the careful wording is that the report describes a demonstrated access path. It is not a public confirmation of a source-code theft.

What to watch next

Operators of self-hosted Discourse should check the official patched releases and rebuild guidance. For OpenAI, the next useful facts would be an independent review of the identity boundary, a clearer account of connected-service limits, and any evidence about other affected systems. The wider lesson is about architecture, not one brand: convenient links between services need limits, monitoring, and a way to contain a failure.

💬 HN comment themes: image-parser RCE, SSO, bounty, and AI

This summarizes commenters' self-reported claims and speculation. The comments do not independently verify the vulnerability, the extent of access, or claims about AI capability and speed.

  • Commenters' reading of the article is that a HEIF image-processing flaw led to server-side RCE and then to internal repositories. That chain is reported by the article and commenters, not independently established here.
  • The biggest technical complaint concerned the SSO step. Commenters said the article explains the image-processing side but not why an ID token for another client could read and write GitHub. Missing audience validation and token replay were proposed as hypotheses, not confirmed facts.
  • Commenters discussing the article put the reported bounty at $6,500. Some considered it too small for a possible source-code leak. Others argued that server-side vulnerabilities may have little black-market demand after patching, and that stealing a repository would be a heist rather than selling the vulnerability. Some also questioned whether the real impact was as large as claimed.
  • Commenters described HEIF and ImageMagick as a broad attack surface because of features such as composition, rotation, cropping, and transparency handling. Suggestions included supporting fewer formats, converting on the client, and combining sandboxing with access controls. A counterpoint was that moving to a memory-safe language alone would not remove logic or input-sanitization bugs.
  • If the reported lateral movement after RCE was real, commenters said sandboxing and least-privilege controls should have limited it. Others worried about designs that give employees with elevated privileges credential rules similar to ordinary customers.
  • The discussion also described Claude being put in an autonomous goal loop against a controlled instance, shown through a CTF-like proxy because it refused a direct remote-target exploit request. This is a reported setup, not a general benchmark of LLM ability.
  • Views on AI were divided: it may lower the cost and increase the speed and scale of both attack and defense, and it might help find and fix more bugs. However, unreviewed AI-written code could also add new RCEs, while attackers may gain easier access to stolen compute or services.

initial digest at 202 comments (revision 1). We fetched 100 comments and sampled 100 across the thread. These are HN users’ reports, not independently verified facts.

🔥 Trending on HN

A picture upload reportedly reached farther than expected at OpenAI, the company behind ChatGPT

📰 Full story: How an image upload reportedly reached internal repositories at OpenAI, the company behind ChatGPT

A security report says one picture upload connected systems unexpectedly.

1 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
Discourse

Software that runs online discussion forums.

SSO

A system that lets one login work across services.

pull request

A proposed code change for review.

💡 The gist

  • Researchers reported a path from an image upload to OpenAI accounts.
  • OpenAI and Discourse said the related issues were fixed.
  • Hacker News attention does not prove the report is true.

Hacktron AI, a team that studies computer safety, published the report. It described OpenAI, the company behind ChatGPT, and a public forum called community.openai.com. The forum uses Discourse, software for online discussions.

The researchers say the forum had a problem in its image-processing software. A specially prepared image could make the forum computer perform unwanted actions. We do not need the technical details to understand the risk.

The forum’s login was connected to OpenAI’s wider sign-in system. The researchers say this connection reached employees’ ChatGPT and Codex accounts. One account had a GitHub connection. They say they reached an internal repository through it. They created a harmless pull request, or proposed code change, as proof. They say they stopped without reading sensitive information.

OpenAI confirmed a fix about 14 hours after the first report, according to Hacktron AI. Discourse also published a security advisory and patches. The supplied record lists 478 points and 202 comments for the Hacker News post. That shows strong attention from the technology community. It does not prove every claim in the report.

The deeper lesson involves connected services. Image uploads, logins, and code tools can each seem harmless. Their connections can create a larger problem. Companies need clear limits between services. They also need fast patches and safe testing. We still do not know how many accounts were reachable. We also do not know whether any sensitive data was viewed. The public report demonstrates a claimed access path, not a confirmed source-code theft.

💬 A simpler summary of the HN comments: image bugs, SSO, bounty, and AI

This is a summary of commenters' self-reported claims and guesses. The comments do not independently prove the vulnerability, its impact, or AI speed.

  • Commenters understood the article to say that a specially made HEIF image broke image processing, allowed code to run on a server, and led toward internal repositories. That is the article's and commenters' account, not an independently verified fact here.
  • The main question was SSO, which lets different services trust a login. Why could an ID token from another app read and write GitHub? Ideas about failing to check the token's intended audience or reusing it were guesses.
  • Comments about the article described the bounty as $6,500. Some said that was too low. Others said a server-side flaw may be hard to sell after it is fixed, and stealing a repository is different from selling a flaw. Some doubted the impact was really as large as claimed.
  • HEIF and ImageMagick handle many complicated image features, so commenters saw them as a large attack surface. They suggested supporting fewer formats, converting images on the user's device, and using sandboxes and permission limits. Changing languages alone would not fix every logic or input-handling error.
  • If an attacker could move from the image server to other systems, stronger isolation and fewer permissions should have reduced the harm. Commenters also worried about giving powerful employee accounts the same credential rules as ordinary customers.
  • The comments described Claude being tried automatically in a CTF-like setup. Some people think AI can make attacks and defenses faster and cheaper; others worry that unchecked AI-written code can create new holes.

initial digest at 202 comments (revision 1). We fetched 100 comments and sampled 100 across the thread. These are HN users’ reports, not independently verified facts.

🔥 Trending on HN

OpenAI, the company behind ChatGPT, had a picture problem

📰 Full story: How an image upload reportedly reached internal repositories at OpenAI, the company behind ChatGPT

A picture made a computer safety worry.

1 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
Codex

A tool that helps write computer code.

Discourse

Software that runs an online talking place.

Hacker News

A website where technology stories get attention.

Hacktron AI is a team that checks computer safety. It wrote about OpenAI. OpenAI makes ChatGPT.

A forum can receive pictures. Discourse is the software running this talking place. The team says a bad picture made the forum computer misbehave.

The forum’s sign-in was connected to OpenAI. That sign-in also connected to ChatGPT and Codex. Codex is a tool for writing computer code.

The team says it reached an inside OpenAI code place. It made a harmless change request there. It says it did not read secret information.

OpenAI said its problem was fixed. Discourse fixed the picture problem too.

The supplied record gives the Hacker News story 478 points and 202 comments. Those numbers show attention. They do not prove the story is true.

People still do not know how many accounts were reachable. They also do not know whether private information was seen. The report shows a safety path. It does not prove that code was stolen.

💬 The image hole and AI, in very simple words

This summarizes what commenters said. The hole and the size of the damage were not verified here.

  • Commenters said the article described a special image using a server weakness and reaching an internal code store. That is a self-reported account, not a fact checked here.
  • People asked why a login key from one app could open GitHub in another app. This was the missing SSO explanation. Some also worried that powerful employee accounts might not get extra protection.
  • Commenters said the reported bounty was $6,500. Some thought it was too small. Others said a fixed hole is hard to sell, and stealing code is a different plan.
  • Complex image tools should run in a small box with few permissions. Claude was reportedly tried in a puzzle-game-like setup. AI may help find problems, but unchecked AI code may create new ones too.

initial digest at 202 comments (revision 1). We fetched 100 comments and sampled 100 across the thread. These are HN users’ reports, not independently verified facts.

Sources