A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
8.9 relevance
Score Breakdown
technical depth 9
novelty 9
actionability 8
community 9
strategic 9
personal 10
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Detailed exploit compromising OpenAI repos, highly actionable and critical for AI security.
Summary
Researchers chained a libheif heap overflow in OpenAI's Discourse forum (community.openai.com) with an SSO misconfiguration to take over employee ChatGPT/Codex accounts, gaining access to internal GitHub repos. The exploit, disclosed via Bugcrowd, was fixed within 14 hours; OpenAI paid a $6,500 bounty. The libheif vulnerability (part of the 'HEIF Heist' investigation) also impacts Slack, Meta, GitHub Enterprise, and Node.js frameworks like Next.js and Astro.
Author
rootxharsh