Case · DiggingBeagle record

Hacktron: image processing, SSO and connected development authority

Hacktron describes a July 2026 defensive-research chain that began with a missing libheif security backport, reached remote code execution in an OpenAI-hosted Discourse forum, crossed an OpenAI SSO boundary, and was demonstrated by asking Codex to open a harmless pull request in an internal repository. The researchers say Claude Opus 4.8 and Opus 5 materially accelerated exploit development, but skilled human guidance remained important and the broader connected-app reach was not demonstrated.

First seen
Jul 25, 2026
Case kind
research
AI role
WITH AI
Claims
8

Reconstruction

Mechanism & boundary

  1. 01

    Step

  2. 02

    Step

  3. 03

    Step

  4. 04

    Step

  5. 05

    Step

  6. 06

    Step

  7. 07

    Step

Timeline

  1. Jul 23, 2026

    Step

  2. Jul 25, 2026

    Step

  3. Jul 25, 2026

    Step

  4. Jul 25, 2026

    Step

  5. Jul 25, 2026

    Step

  6. Jul 27, 2026

    Step

  7. Jul 28, 2026

    Step

  8. Sep 13, 2026

    Step

Claims & evidence

reported findingsupported

Hacktron reports a July 25 chain from Discourse image processing through an OpenAI SSO flaw into employee ChatGPT/Codex accounts, demonstrated with a harmless internal pull request.

  • supports
    Hacking OpenAI

    Locator: Intro; disclosure timeline; Opus 5 Released

reported findingsupported

The authors identify Opus 4.8 and Opus 5. They say they did not read internal code; access to other connectors was potential rather than demonstrated.

reported findingsupported

The sub-$3,000 token figure covers broader multi-company research. The $6,500 award covered the OpenAI-side finding; the quoted scope clarification excludes testing the Discourse-hosted forum from that bounty.

  • supports
    Hacking OpenAI

    Locator: Costs of finding these vulnerabilities; disclosure timeline item 9

reported findingsupported

Discourse advisory GHSA-vhm9-85gw-x335 associates CVE-2026-32882 with the HEIF processing flaw and supplies patch/rebuild guidance.

reported findingsupported

The researchers demonstrated internal development authority by having Codex open a harmless pull request, while stating that they did not read internal OpenAI source code.

  • supports
    Hacking OpenAI

    Locator: OpenAI employee account/Codex proof-of-access section

reported findingsupported

OpenAI fixed the account-takeover path on July 25, and Discourse subsequently published a HEIF advisory and image-processing mitigations.

reported findingsupported

Hacktron says Claude materially accelerated exploit development, including an autonomous loop against a researcher-controlled Discourse instance, but skilled human guidance remained important and the work was not completely autonomous.

  • supports
    Hacking OpenAI

    Locator: sections describing Opus 4.8/Opus 5 exploit development and the /goal loop

reported findingsupported

The disclosure discusses broader potential access through connected services, but it does not establish that those additional services were actually accessed.

  • supports
    Hacking OpenAI

    Locator: discussion of connected applications and stated stopping point

Implications

Connected-account authority should be reviewed as a chain. Image-processing, SSO and developer integrations can turn a narrow foothold into wider effective authority even when the model itself is not the security boundary.

Controls & mitigations

  • OpenAI fixed the SSO account-takeover path on July 25.
  • Discourse rebuilt/patched the affected image-processing stack and documented image sandboxing.
  • Operators using vulnerable HEIF/AVIF processing should update the relevant dependency chain or disable/sandbox untrusted HEIF/AVIF processing where updating is not immediately possible.

What remains unknown

  • Broader unauthorized exploitation or customer loss is not established.
  • A later bounty award does not establish authorization for every earlier forum action.

Cite this record

DiggingBeagle. “Hacktron: image processing, SSO and connected development authority.” First seen Jul 25, 2026. https://diggingbeagle.com/cases/hacktron-image-processing-sso-and-connected-development-authority/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.