Cybersecurity Research

Researchers Chained Two Bugs to Hijack OpenAI Staff Accounts via Help Forum

Hacktron · 13 Sept 2026
Key Takeaway If your business uses third-party forum or helpdesk software connected to internal accounts, keep it patched and limit how many other services those accounts can access.

Security researchers at Hacktron discovered they could chain two critical vulnerabilities to compromise ChatGPT accounts belonging to OpenAI employees. The flaws stemmed from OpenAI's community help forum, built on the Discourse platform, which allowed remote code execution and administrative access to the forum's backend. Because employees had connected services like GitHub, Slack and email to their Codex and ChatGPT accounts, the potential blast radius of this access was significant.

To prove the access without viewing sensitive data, the researchers used a compromised employee's Codex account to open a harmless pull request in OpenAI's internal code repository. The entire process, from discovery to gaining repository access, took less than 72 hours. The team reported the issue through OpenAI's Bugcrowd program and Discourse's HackerOne program rather than exploiting it further, and OpenAI paid a $6,500 bounty for the disclosure.

Both OpenAI and Discourse responded quickly. OpenAI confirmed a fix within 14 hours of the report, while Discourse had a patch ready within days and added extra sandboxing protections around image processing. Discourse has since published a public security advisory with patch and rebuild guidance for other organisations running the same software.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Hacktron. We link back to every original so you can read it yourself.