HEIF upload: native decoder RCE followed by an SSO trust pivot

HEIF upload: native decoder RCE followed by an SSO trust pivot
Hacktron chained two separate flaws to move from a low-privileged account on OpenAI's public Discourse forum to write access in an internal GitHub repository. A crafted HEIF upload yielded RCE through libheif; a separate SSO flaw then turned control of the forum into ChatGPT/Codex session takeover.
Discourse did not handle HEIC/HEIF with its primary FastImage parser. The upload pipeline passed the file to ImageMagick, which loaded libheif 1.19.7 from the Debian 12 image. Upstream had already changed the vulnerable overlay logic, but the unlabeled commit never reached the downstream package.
For a negative overlay offset, a signed value entered unsigned bounds arithmetic, corrupting the region size and driving copy loops outside heap buffers. Hacktron adapted the OOB read/write primitive to ASLR, x86-64, and jemalloc, then obtained RCE in the forum environment.
A separate OpenAI SSO identity flaw turned the forum compromise into ChatGPT/Codex session takeover. One employee account had a GitHub connector, and the researchers used its Codex to create PR #1186742 in the internal monorepo as a minimal proof of write access.
The malformed image, exploit, and SSO trace are not public. Discourse also maps the RCE to CVE-2026-32882, while upstream assigns that ID to a distinct read-only bug; Hacktron's write-capable flaw has no separate CVE.
Vulnerabilities
8.5
CVE-2026-32882
Vendors
Openai
Discourse
Github
Debian
Imagemagick
Products
Chatgpt
Codex
Debian 12
Discourse
Fastimage
Github
More