Risky Business · Wednesday, September 23, 2026
A group of security researchers, Hectron, discovered a vulnerability in OpenAI's Discourse forum software that allowed them to exfiltrate tokens. These tokens were not only usable for forum access but also for logging into ChatGPT and subsequently accessing linked services like GitHub.
“Yeah, and it looks like they're not real good at scoping tokens either, because, uh, it looks like they got owned by some, some hacker bros, uh, who may have.”
“It is. Uh, so, so this was back in, uh, July 25th, uh, these three cyber bros from Hectron, I think they're called, they were doing basically research into image passing and particularly the, uh, HEIF format.”
“Who runs Discourse to run their forums? None other than OpenAI. So they deployed, they basically used these vulnerabilities to, uh, pop remote code execution in OpenAI's forum instance of their Discourse forum, and were able to exfiltrate tokens.”
“And what they then determined was that the tokens they'd exfiltrated from the Discourse forum, didn't just work to authenticate users on to the forum, but the exact same tokens could be used to sign in to ChatGPT.”