Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.

OpenAI’s forum is powered by an open-source discussion board platform called Discourse.

Under the hood, the software processes images with the help of an open-source tool called libheif.

The proof-of-concept worked well in their internal Discourse instance, but didn’t carry over to OpenAI’s forum because it uses a safeguard called ASLR.

The libheif vulnerability that exposed OpenAI’s code is one of several exploits in the image processing tool.