AI Agents Gain Access to OpenAI Internal Repositories... Opus 5 Generates Exploit in ASLR Environment in 3 Hours
Key point
The HacktronAI team used AI agents to gain access to OpenAI internal repositories, while the Claude Opus 5 model generated an exploit in an ASLR-enabled environment in just 3 hours, indicating a rapid improvement in AI models' vulnerability development capabilities.
Details
The HacktronAI team successfully used AI agents to access OpenAI's ChatGPT and Codex accounts and internal repositories. This attack was carried out through an Exploit Chain that linked a vulnerability in the libheif image decoder to a misconfiguration in OpenAI SSO.
AI Models' Vulnerability Development Capabilities
The performance differences among the AI models used in the attack were notable. Claude Opus 4.8 struggled with vulnerability development in environments where ASLR (Address Space Layout Randomization) was enabled, but Claude Opus 5 generated an exploit for ARM64 environments within 3 hours of its release. It was reported that switching to GPT-5.6 Sol significantly increased the ability to exploit vulnerabilities without target system information.
Attack Path and Impact
The attacker obtained RCE (Remote Code Execution) in the Discourse environment at community.openai.com and then used a vulnerability in OpenAI SSO to hijack employee accounts. This allowed them to prove access by creating a Pull Request in OpenAI's internal monorepo (openai/openai). HacktronAI warned that this vulnerability stems from OpenAI SSO configuration issues, not Discourse itself, and that similar intrusions are possible in other services using SSO.
Security Implications and Response
In the past, complex vulnerability development required rare expertise and time, but AI is replacing this with computing resources, compressing attack preparation time. HacktronAI is tracking vulnerabilities across HEIF/AVIF image processing apps and recommends updating to the latest libheif version and sandboxing image decoding. OpenAI patched the vulnerability approximately 14 hours after the report and paid a bounty of $6,500.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.