The news
Primaries: Hacktron, Hacking OpenAI (13 September 2026) and Discourse GHSA-vhm9-85gw-x335 (28 July 2026).
Hacktron reports that compromising community.openai.com via a HEIF image-upload path, then abusing an OpenAI SSO identity flaw, allowed takeover of ChatGPT and Codex accounts for active forum users. Impact proof: a prompt to an employee's connected Codex opened a harmless PR in an internal monorepo. OpenAI confirmed an OpenAI-side fix the same day as the report. Discourse patched and published the GHSA. OpenAI paid $6,500 on 1 September 2026, scoped to the SSO finding.
Why it matters
Coding agents connected to GitHub turn an identity bug into a source-control event. Forum hosts that share SSO with product sessions sit inside the same blast radius as the IdP.
What to do now
- Inventory services that share SSO with ChatGPT, Codex, or similar agent products.
- Self-hosted Discourse admins: follow GHSA rebuild guidance (
git pulland./launcher rebuild app). Do not assume a web-only upgrade replacedlibheifin the image. - Security reviewers: read Hacktron's bounty-scope note. Forum testing excluded from OpenAI's program still fed an in-scope identity finding.
No PoC
This dispatch stays at trust-boundary and disclosure level. It does not include exploit steps, payloads, or reproduction procedures.
