OpenAI Fixes Account Flaws Exposed by AI-Assisted Hackers
OpenAI has fixed vulnerabilities that researchers used to compromise employee accounts with AI assistance, according to reporting published September 18. The Guardian reports that the company acknowledged the findings and addressed the flaws.
The case highlights a practical security issue: an AI account can provide a route into the services attached to it. Hacktron says it demonstrated that risk by getting an employee’s Codex account to create a harmless pull request in an internal repository.
What Was Announced
In its original security disclosure, Hacktron dates the compromise to July 25 and its disclosure to September 13. Today’s coverage concerns an earlier incident, not an attack first discovered today.
OpenAI told Business Insider that it restricted Community sign-in token permissions and revoked affected tokens and sessions. Hacktron received a $6,500 bounty; its disclosure includes OpenAI’s clarification that the reward covered the OpenAI-side finding, while testing the Discourse-hosted forum fell outside its bounty scope.,
How It Works

The researchers chained an image-processing vulnerability with an OpenAI sign-in configuration flaw. That combination turned forum access into access to ChatGPT and Codex accounts, according to Hacktron.
Discourse independently confirms that a flaw in the libheif image library allowed uploaded images to trigger remote code execution—running code on the affected server. Its advisory lists patched releases and additional isolation for image processing.
What This Means for Users
The reports reviewed do not establish a mass theft of ordinary users’ chats. Business Insider reports that the researchers stopped after demonstrating the internal code-change request and notified OpenAI.
For self-hosted Discourse administrators, the concrete action is to rebuild using the patched Docker image described in the advisory. Discourse also added image-processing sandboxing on supported systems to limit the reach of similar vulnerabilities.
What’s Next
Discourse has already published remediation guidance. The next operational step for affected self-hosted installations is applying it; the advisory does not require waiting for a future release.
For more AI news and analysis, visit knowaidata.com.