CVE Tools

Исследователи использовали Claude, чтобы взломать сотрудников OpenAI

Хакер (xakep.ru)By Мария Нефёдова

PoC publiccommunity.openai.comImageMagick

Our summary

Hacktron researchers used Claude Opus 5 to build an exploit chain targeting community.openai.com, an OpenAI forum running Discourse, and gained access to several employees' ChatGPT and Codex accounts. The public PoC combined CVE-2026-32882 in libheif with an OpenAI SSO issue; the server used libheif 1.19.7 despite a fix in 1.22.0, enabling forum RCE and potential access to connected internal services. OpenAI remediated the issue after disclosure, while Discourse added image-processing sandboxing.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store