Document

  • ID: GHSA-vhm9-85gw-x335
  • Title: RCE via malformed HEIF file
  • Publisher: discourse/discourse (davidtaylorhq)
  • Published: 28 July 2026
  • Severity: High - CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
  • Upstream reference in advisory text: libheif CVE-2026-32882
  • Credits: hacktronai-research (Reporter)

Affected / patched (as listed)

Advisory lists affected version trains including >= 0 and dated *-latest lines (2026.6.0-latest, 2026.5.0-latest, 2026.1.0-latest among those shown on the advisory page).

Patched versions listed: 2026.7.0, 2026.6.1, 2026.5.2, 2026.1.6.

Description (advisory paraphrase)

An upstream vulnerability in libheif allows remote code execution via Discourse image uploads. The latest Discourse Docker image includes the patched libheif. Update as normal via ./launcher rebuild app. Latest supported Discourse core versions also add sandboxing for image processing as defense in depth where the kernel supports it.

Operator extract

From the advisory and Hacktron's aligned patch notice for self-hosters:

  • Rebuild the container image. A web-UI-only update may not replace the underlying decoder package.
  • Discourse-hosted customers were already patched per the advisory text.

Related narrative document

Hacktron's "Hacking OpenAI" places this advisory inside a longer chain that also involved an OpenAI SSO issue. The GHSA itself addresses the Discourse/libheif upload path. It does not document OpenAI SSO.

Reading rule

Use this Record for patch status and rebuild instructions. Use the Hacktron post for identity-boundary narrative. Do not treat the GHSA as a PoC.