Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude

AI Staff Writer

Security Researchers Exploit OpenAI’s GitHub Repository Using AI

Three cybersecurity researchers successfully breached OpenAI Group PBC’s GitHub repository utilizing Claude, an AI model developed by Anthropic. According to sources that spoke with the Wall Street Journal, this repository contained vital algorithmic information belonging to OpenAI. The files remained exposed until June 24, when the researchers informed the company of the vulnerabilities, prompting OpenAI to release a patch within 14 hours of the report.

Vulnerabilities Identified in OpenAI’s Infrastructure

The researchers are affiliated with Hacktron AI Inc., a venture-backed cybersecurity startup. In a detailed blog post, Hacktron described how their investigation uncovered two vulnerabilities within OpenAI’s system architecture. One vulnerability was linked to the company’s user forum, while the other affected its single sign-on (SSO) system responsible for managing employee accounts.

Discourse Vulnerability Exploited

OpenAI’s forum operates on Discourse, an open-source discussion platform that allows users to upload images within their posts. To handle these images, the platform uses an open-source library called libheif, where Hacktron’s researchers identified the initial vulnerability. This flaw allows hackers to exploit certain versions of libheif by uploading crafted images that trigger a buffer overflow, thereby permitting unauthorized modifications to program data.

Patching Lag Contributes to Breach

Although the developers of libheif had issued a patch to address this vulnerability approximately a year prior to Hacktron’s findings, Discourse failed to implement the update, leaving OpenAI’s forum exposed to attacks. Hacktron’s team created the first version of their exploit on June 23, deploying Claude Opus 4.8. While effective on their internal Discourse setup, it could not be replicated on OpenAI’s forum due to an additional security measure known as Address Space Layout Randomization (ASLR).

Breakthrough Achieved with Enhanced AI Model

The researchers made a significant breakthrough on June 24 when Anthropic launched Claude Opus 5. This newer iteration allowed the researchers to bypass OpenAI’s ASLR security mechanism. Gaining access to the forum enabled them to identify a configuration flaw within the SSO system, which governs access to accounts of OpenAI employees—as well as to sensitive internal resources.

Scope of the Compromise and Responsible Disclosure

Approximately three hours after breaching the forum, Hacktron alerted OpenAI about the discovered vulnerabilities. Following this communication, the researchers managed to access an OpenAI employee’s account, which provided insights into the scope of the security issues at hand and unauthorized entry into the company’s internal GitHub environment.

HEIF Heist Vulnerabilities Affect Multiple Companies

The vulnerability tied to libheif that compromised OpenAI’s code is part of a larger exploit series dubbed HEIF Heist. Hacktron has found that this issue is not limited to OpenAI but affects other major tech firms, including Salesforce Inc.’s Slack and Meta Platforms Inc. It is believed that the widespread nature of the HEIF Heist is due, in part, to the absence of an entry for this bug in the Common Vulnerabilities and Exposures (CVE) database, complicating efforts for developers to identify and remediate affected systems. Hacktron advises users to install the latest versions of libheif and to bolster or disable their image processing workflows to mitigate potential risks.

[gspeech type=full]

Share This Article
Leave a comment