Cybersecurity researchers gain access to OpenAI’s GitHub repository using Claude
Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.
Sources told the Wall Street Journal today that the repository contains “OpenAI’s algorithmic secrets.” The files were accessible until June 24, the day the researchers reported their findings to the company. OpenAI released a patch within 14 hours of receiving the tip.
The exploit’s discoverers work at a venture-backed cybersecurity startup called Hacktron AI Inc. The company detailed in a blog post that the issue stemmed from two vulnerabilities in OpenAI’s infrastructure. One affected the company’s user forum while the other was found in the single single-on, or SSO, system that manages employee accounts.
OpenAI’s forum is powered by an open-source discussion board platform called Discourse. Discourse allows users to upload images as part of their posts. Under the hood, the software processes images with the help of an open-source tool called libheif. That tool contained the first vulnerability spotted by Hacktron’s researchers.
The vulnerability enables hackers to compromise certain versions of libheif by uploading a malicious image. The malware-laden file causes a bug known as buffer overflow, which makes it possible to edit program data that is normally inaccessible. Hackers can replace the program data with malicious code.
The developers of libheif patched the issue about a year before Hacktron’s researchers made their discovery. However, Discourse didn’t implement the patch, which left OpenAI’s forum vulnerable.
Hacktron’s researchers developed the initial version of the exploit on June 23 using Claude Opus 4.8. The proof-of-concept worked well in their internal Discourse instance, but didn’t carry over to OpenAI’s forum because it uses a safeguard called ASLR. The technology protects sensitive program data from buffer overflows by spreading it over randomized memory locations.
The researchers’ breakthrough came the following day, when Anthropic released Claude Opus 5. The model quickly found a way around OpenAI’s ASLR implementation. After the researchers gained access to the company’s forum, they found a configuration issue in the SSO system that powers OpenAI employees’ forum accounts. The same SSO system manages staffers’ access to sensitive internal systems.
Hacktron’s researchers notified the company about the issue about three hours after they compromised its forum. From there, they took over an OpenAI employee’s account to map out the scope of the issue. That account gave them access to the company’s internal GitHub environment.
The libheif vulnerability that exposed OpenAI’s code is one of several exploits in the image processing tool. Hacktron has named the bug series HEIF Heist. The company discovered it in the infrastructure of not only OpenAI but also Salesforce Inc.’s Slack, Meta Platforms Inc. and other major tech firms.
It’s believed HEIF Heist is so widespread because libheif’s developers didn’t create an entry for the bug series in the CVE vulnerability database. That made it more difficult for developers to detect and patch vulnerable systems. Hacktron is advising affected users to download the latest versions of libheif and harden or disable their image processing pipelines.
Photo: Unsplash
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.