Hacktron: image processing, SSO and connected development authority
Hacktron describes a July 2026 defensive-research chain that began with a missing libheif security backport, reached remote code execution in an OpenAI-hosted Discourse forum, crossed an OpenAI SSO boundary, and was demonstrated by asking Codex to open a harmless pull request in an internal repository. The researchers say Claude Opus 4.8 and Opus 5 materially accelerated exploit development, but skilled human guidance remained important and the broader connected-app reach was not demonstrated.
Hacktron reports a July 25 chain from Discourse image processing through an OpenAI SSO flaw into employee ChatGPT/Codex accounts, demonstrated with a harmless internal pull request.
The sub-$3,000 token figure covers broader multi-company research. The $6,500 award covered the OpenAI-side finding; the quoted scope clarification excludes testing the Discourse-hosted forum from that bounty.
The researchers demonstrated internal development authority by having Codex open a harmless pull request, while stating that they did not read internal OpenAI source code.
Hacktron says Claude materially accelerated exploit development, including an autonomous loop against a researcher-controlled Discourse instance, but skilled human guidance remained important and the work was not completely autonomous.
Locator: sections describing Opus 4.8/Opus 5 exploit development and the /goal loop
reported findingsupported
The disclosure discusses broader potential access through connected services, but it does not establish that those additional services were actually accessed.
Locator: discussion of connected applications and stated stopping point
Implications
Connected-account authority should be reviewed as a chain. Image-processing, SSO and developer integrations can turn a narrow foothold into wider effective authority even when the model itself is not the security boundary.
Controls & mitigations
OpenAI fixed the SSO account-takeover path on July 25.
Discourse rebuilt/patched the affected image-processing stack and documented image sandboxing.
Operators using vulnerable HEIF/AVIF processing should update the relevant dependency chain or disable/sandbox untrusted HEIF/AVIF processing where updating is not immediately possible.
What remains unknown
Broader unauthorized exploitation or customer loss is not established.
A later bounty award does not establish authorization for every earlier forum action.
DiggingBeagle. “Hacktron: image processing, SSO and connected development authority.” First seen Jul 25, 2026. https://diggingbeagle.com/cases/hacktron-image-processing-sso-and-connected-development-authority/
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.