Tools AI Risk Radar ai-incident-0088
Incident record
A forum exploit chained with an SSO flaw walked researchers into OpenAI internal code
- Severity
- Critical
- Status
- Contained
- Type
- Data Leak
- Target
- OpenAI community forum, an employee's ChatGPT and Codex accounts, and an internal repository
- Actor
- researcher
- CVE
- CVE-2026-32882
What happened
Security firm Hacktron AI chained a libheif heap-overflow remote code execution in the Discourse forum software with an SSO misconfiguration on OpenAI's community forum, took over an employee's ChatGPT and Codex accounts, and opened a pull request inside an OpenAI internal repository. OpenAI shipped a fix roughly fourteen hours after disclosure, marked the report resolved on 1 September, and paid a bounty.
The underlying Discourse flaw is CVE-2026-32882, patched in Discourse 2026.7.0. The account of the intrusion is the researchers' own write-up, published 13 September; OpenAI has published no page naming the incident.
Sources
- Hacktron AI's write-upwww.hacktron.ai/blog/hacking-openai
- Discourse advisory GHSA-vhm9-85gw-x335github.com/discourse/discourse/security/advisories/GHSA-vhm9…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026