What happened
Hacktron fed Claude an outline of a libheif bug and got back a working RCE payload that runs whenever Discourse processes a HEIC upload.
The payload was run on a test Discourse instance and on OpenAI’s public community forum, where the forum’s sign‑in integration handed the attacker a token that could act as any OpenAI user.
Why it matters
With that token the researchers logged in as an employee, read private‑repo metadata and opened a pull request against an internal OpenAI repository – a clear route to influence production code.
Technical walk‑through
Discourse only checks image MIME types; it does not recognise HEIC/HEIF. An upload is handed to ImageMagick, which loads libheif. The upstream libheif bug (fixed a year ago, never CVE‑ed) allows crafted HEIC files to execute arbitrary commands.
Claude, prompted with the bug description, produced C code that triggers the overflow and writes a reverse shell. Hacktron compiled it, uploaded the malicious HEIC, and achieved remote code execution on the forum host.
OpenAI’s community forum uses OpenAI’s single‑sign‑on. The RCE script called the sign‑in endpoint, obtained a token with "full API" scopes, then used it to authenticate as any OpenAI employee. The token let the attacker call the ChatGPT and Codex APIs as the employee and also query internal GitHub repositories.
Who’s affected
- Discourse sites that accept HEIC uploads and run ImageMagick without sandboxing.
- OpenAI employees who signed into the community forum with their OpenAI credentials.
- Any organization that re‑uses the same sign‑in tokens for internal services.
Defensive steps
- Upgrade Discourse to the version that disables HEIC processing or that runs image handling inside a container.
- Patch ImageMagick and libheif to the latest releases; verify the upstream fix is applied.
- Implement strict token scopes – a sign‑in token should never grant full API access.
- Rotate all tokens issued for the community forum and audit token usage logs.
- Enable image‑processing sandboxing (e.g., Firejail, seccomp) to limit what a compromised library can do.
- Participate in bug‑bounty programs; the $6,500 reward shows responsible disclosure works.
Response timeline
- Hacktron reported the token issue via Bugcrowd; OpenAI revoked the tokens and fixed the permission model within ~14 hours.
- The libheif flaw was reported through HackerOne; Discourse pushed a patch and added sandboxing within two days.
