A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

Security researchers discovered a chain of vulnerabilities in OpenAI's help forum that allowed them to compromise employee accounts and access internal repositories. The team responsibly disclosed the flaws, which were patched, and received a bounty for their findings.
Why it matters
The incident demonstrates the significant security risks posed by SSO misconfigurations and the importance of bug bounty programs in protecting sensitive AI infrastructure.
On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors.
To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee’s Codex to open a PR #1186742 in OpenAI’s internal monorepo openai/openai .
Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum ( community.openai.com ) could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.
The entire timeline from initial discovery to access to OpenAI repo access took place in less than 72 hours.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in