Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.
OpenAI’s forum is powered by an open-source discussion board platform called Discourse.
Under the hood, the software processes images with the help of an open-source tool called libheif.
The proof-of-concept worked well in their internal Discourse instance, but didn’t carry over to OpenAI’s forum because it uses a safeguard called ASLR.
The libheif vulnerability that exposed OpenAI’s code is one of several exploits in the image processing tool.