Three security researchers say they use Anthropic’s Claude models to develop a chained exploit that breaches OpenAI employee accounts and reaches internal code resources. The account access route begins with an image upload on OpenAI’s public help forum, which is powered by Discourse. Sources describe a vulnerability in image processing (linked to libheif/ImageMagick decoding) that allows maliciously crafted content to trigger remote code execution on the forum’s side. A second issue in OpenAI’s shared sign-in flow then lets a compromised forum session carry permissions that extend to connected services such as ChatGPT and Codex, and an associated link to GitHub.

The researchers—Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini—present the demonstration as proof of access rather than broader exploitation. They reportedly used a connected Codex account to submit a harmless pull request to OpenAI’s internal GitHub repository and then stopped testing. OpenAI confirms it fixed the sign-in issue about 14 hours after receiving the report and says it paid a $6,500 bounty; Discourse separately addressed the forum-side flaw on a later schedule.

Outlets emphasize different themes: one highlights the low cost and speed enabled by AI-assisted exploit development, while another places the incident within a broader pattern of cybersecurity concerns involving AI systems and testing environments. Across reports, the core event is a reported July breach tied to forum authentication and image-processing weaknesses.