Hackers successfully exploited two critical vulnerabilities to gain access to multiple OpenAI employees' ChatGPT and Codex accounts on July 25, 2026. This access allowed them to view internal OpenAI repositories, and they demonstrated this by opening a pull request in OpenAI's internal monorepo. The vulnerabilities stemmed from an SSO misconfiguration in OpenAI's identity infrastructure and a libheif RCE in the community forum used by OpenAI. The researchers reported the issue to OpenAI, which was patched within 14 hours, and a $6,500 bounty was awarded, though OpenAI clarified the bounty was for the OpenAI-specific finding, not the Discourse forum vulnerability. AI
IMPACT Highlights the critical need for robust security practices across all integrated services, not just core AI platforms.
RANK_REASON Security researchers disclosed vulnerabilities in a third-party forum used by OpenAI, leading to a limited compromise of employee accounts.
Read on Hacker News — AI stories ≥50 points →
- Bugcrowd
- ChatGPT
- codex
- Discourse
- GHSA-vhm9-85gw-x335
- GitHub
- Hackerone
- HacktronAI
- Harsh Jaiswal
- Mohan Pedhapati
- OpenAI
- Rahul Maini
- Slack
- Twitter X
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →