September 18, 2026
OpenAI's internal repository reached through ChatGPT: attack took less than 72 hours
On July 25, 2026, Hacktron researchers used compromised ChatGPT accounts belonging to OpenAI employees to open a harmless pull request in an internal monorepo. According to their data, less than 72 hours passed from investigating the vulnerability to gaining repository access. OpenAI fixed its part of the issue, revoked affected tokens and sessions, and narrowed Community sign-in permissions.

The vulnerability began on a Discourse forum. Then a heap overflow in libheif led to RCE, an OpenAI SSO flaw opened the way to ChatGPT and Codex, and the chain reached GitHub and an internal pull request. For practitioners, this marks an important boundary: a connected agent becomes part of the code-access perimeter rather than remaining a separate generation window. Claude Opus 4.8 failed to exploit the issue, while Claude Opus 5 created a working ARM64 exploit in a few hours. Discourse fixed the vulnerability in versions 2026.7.0, 2026.6.1, 2026.5.2, and 2026.1.6; for self-hosted installations, the recommended command is `./launcher rebuild app`.
OpenAI paid Hacktron $6,500 through its bug bounty, even though testing the Discourse forum was outside the program's formal scope.
