Technology
Researchers access OpenAI internal systems by chaining software vulnerabilities
A cybersecurity firm breached employee accounts and opened a test pull request before OpenAI issued a patch.
The short version
- Researchers from Hacktron breached employee ChatGPT and Codex accounts by chaining a Discourse forum flaw with an OpenAI single sign-on misconfiguration.[Hacker News]
- The team demonstrated access by opening a proof-of-concept pull request in an internal OpenAI repository, causing no harm to company systems.[Hacker News]
- OpenAI confirmed the issue was patched and awarded the researchers a $6,500 bug bounty for the discovery.[Hacker News]
- There is no evidence that malicious actors exploited the same vulnerabilities prior to the fix.[NBC News]
Key facts
- Hacktron researchers combined a heap buffer overflow in Discourse's image processing library with an OpenAI SSO misconfiguration to compromise employee accounts.[Hacker News]
- The entire process from initial vulnerability discovery to internal repository access took under 72 hours.[Hacker News]
- OpenAI paid the researchers a $6,500 bug bounty after confirming the internal fix roughly 14 hours after disclosure.[NBC News · Hacker News]
- AI models, including Claude Opus versions, were utilized with human guidance to develop and refine the exploit.[Hacker News]
Sources
Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.
- Hacking OpenAIHacker News
- Hackers breached OpenAI, adding to fever pitch of security and safety concernsNBC News - Top Stories