AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Summary
Researchers used Claude (an AI assistant) to build a working exploit for an unpatched bug in a third-party image library, then chained it with a flaw in OpenAI's sign-in system to gain remote code execution (the ability to run commands on someone else's computer) on OpenAI's community forum and take over employee accounts. The vulnerability stemmed from the forum accepting image uploads that were processed by ImageMagick with an outdated library, combined with sign-in tokens that granted excessive permissions to linked ChatGPT and GitHub accounts.
Solution / Mitigation
OpenAI narrowed the permissions on community sign-in tokens and revoked affected tokens and sessions. Discourse released a fix within two days that included image-processing sandboxing as an additional layer of defense, and published a security advisory.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/
First tracked: September 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%