Skip to finding
important · Zero-click — Identity

A forum image upload could cross OpenAI SSO into an active member's ChatGPT and Codex accounts.

Affects

Discourse forums that process HEIF uploads with vulnerable libheif builds, when connected to OpenAI SSO services.

A low-privilege Discourse user could upload a crafted HEIF image, turn a libheif overflow into server-side execution, and compose that compromise with an OpenAI SSO trust-boundary flaw.

Detail and 2 sources

The demonstrated no-interaction transition took over an active account and used an employee's Codex connection to open an internal-repository pull request.

Discourse publishes patched releases for the image-processing flaw.

The published fix was not read for this brief, so this cannot lead.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026