Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

ImageMagick Path Led Researchers to OpenAI’s Internal GitHub

Security researchers at Hacktron AI said a chain of vulnerabilities and a sign-on misconfiguration let them reach OpenAI’s internal GitHub through the company’s community forum. The work also revived an uncanny detail in a 2020 xkcd comic: its hover text mentioned ImageMagick breaking.

Hacktron said the forum runs on Discourse, whose FastImage component hands unsupported HEIF images to ImageMagick for conversion. ImageMagick calls libheif to decode the files. The version of libheif supplied through Debian had a heap buffer overflow that had been fixed the previous year, but had not been labeled a potential security risk.

The researchers chained exploits with a secondary single sign-on (SSO) misconfiguration, which they said let a community account signed in through the forum reach ChatGPT and Codex accounts. They made what they described as a harmless pull request as proof of concept and notified OpenAI. OpenAI patched the issue 14 hours later and awarded the team a $6,500 bug bounty. Discourse later rated the image bug 8.8 on the CVSS scale and added sandboxing for image processing.

Hacktron said the same image decoders also appear in software and services including Slack, Meta, GitHub Enterprise, Ruby on Rails, and frameworks such as Next.js, Astro, and Gatsby. The team said three researchers used Anthropic’s Claude Opus 4.8 before switching to Opus 5, spent under $3,000 on tokens, and prepared an exploit in two months. The report says AI accelerated the work but was not required to carry it out.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.