Researchers Prove Access Path to OpenAI Internal Code Repository Using Anthropic Model

Three researchers from security firm Hacktron AI reportedly gained access to OpenAI employees' ChatGPT accounts and internal code repositories by leveraging the Anthropic Claude model. VentureBeat reported that the team exploited vulnerabilities in HEIC/HEIF image processing on OpenAI's community forum, which allowed them to breach the forum server. From there, they bypassed OpenAI's SSO configuration issues to access some employees' ChatGPT and Codex accounts. The researchers then created a pull request proposing harmless changes to OpenAI's internal monorepo via Codex to demonstrate their access, without viewing sensitive source code. They reported the vulnerability to OpenAI's bug bounty program on July 25 and received $6,500 in compensation. OpenAI reportedly fixed the issue the same day, while Discourse announced a security advisory on July 28 addressing image upload-related remote code execution vulnerabilities.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 연구진 3명, 앤트로픽 모델로 오픈AI 내부 코드 저장소 접근 경로 입증