A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Researchers chained a libheif heap overflow in OpenAI's Discourse forum (community.openai.com) with an SSO misconfiguration to take over employee ChatGPT/Codex accounts, gaining access to internal GitHub repos. The exploit, disclosed via Bugcrowd, was fixed within 14 hours; OpenAI paid a $6,500 bounty. The libheif vulnerability (part of the 'HEIF Heist' investigation) also impacts Slack, Meta, GitHub Enterprise, and Node.js frameworks like Next.js and Astro.