Researchers at security firm Hacktron AI used Anthropic's Claude to help discover vulnerabilities and gain access to multiple OpenAI employee ChatGPT accounts. From one of these accounts, the team showed they could reach the AI lab's internal software repositories.
Three researchers - Harsh Jaiswal, Mohan Pedhapati and Rahul Maini - said they obtained remote code execution (RCE) and administrative access to the Discourse environment on OpenAI's community forum on July 25, which they used to exploit an identity-system flaw.
This allowed a compromised forum session to take over ChatGPT and Codex accounts. One of those compromised accounts had Codex connected to GitHub.
"To demonstrate the practical impact of the vulnerability, we created a harmless proof-of-concept pull request in OpenAI's internal monorepo," the team explained.
The researchers specifically used Claude to examine how the community forum processed HEIC and HEIF image uploads and to write an exploit targeting a bug in the image upload pipeline. While Opus 4.8 could not produce a reliable exploit, Opus 5 succeeded in producing one in a test setting within a few hours, researchers said. The entire timeline from initial discovery to accessing the repository took less than 72 hours.
"Until two months ago, any user or OpenAI employee logging into OpenAI's own help forum could have had their ChatGPT and Codex accounts taken over," the researchers wrote in their report. "Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails."
The Hacktron AI researchers reported the vulnerability to OpenAI and Discourse, and received a $6,500 bounty for the OpenAI-side finding. OpenAI confirmed with the team that the bug had been fixed, roughly 14 hours after the report. Discourse also patched the bug in the following days.
Security must 'catch up'
This discovery comes at a time when AI development has drastically lowered the cost of launching a serious security exploit.
"This was not completely autonomous hacking, and skilled human guidance remained important, but the amount of work a small team could perform increased dramatically," the team noted.
The Hacktron AI team stated that security assumptions "must catch up" with attacker capabilities, as AI has removed the layer of complexity in online security that previously required rare expertise and significant time to crack.
"A realistic threat model should take into account the economics of exploitation today, instead of relying on outdated assumptions about who can carry out sophisticated attacks," the team said.
