SAN FRANCISCO: An OpenAI ethical hack let cybersecurity researchers access employee accounts. They also demonstrated access to a private code repository after using Anthropic’s Claude to help develop the exploit.
Researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of Hacktron AI began testing on July 23. They later reported the vulnerabilities to OpenAI and stopped without examining proprietary source code.
The Wall Street Journal reported that the team used Claude Opus 5 while developing the attack. The Guardian said the researchers also used OpenAI’s GPT-5.6 Sol during parts of the operation.
The initial vulnerability affected OpenAI’s community forum, which runs on the third-party Discourse platform. According to Hacktron’s account, image uploads passed through ImageMagick and a vulnerable version of the libheif decoding library.
The researchers said specially crafted data enabled remote code execution on the forum server. A separate sign-on weakness then let the team access active user accounts, including those of OpenAI employees.
The researchers said the access could extend to connected services such as GitHub. They demonstrated the risk using an employee-linked development account.
Read: OpenAI AI Safety Framework Tracks Six Concerning Cases
The team created a harmless pull request in a private OpenAI repository without reading the underlying code.OpenAI paid Hacktron AI $6,500 under its bug bounty program, according to the Wall Street Journal and the researchers.
An OpenAI spokesperson thanked the team for reporting its findings and said the company had addressed the vulnerabilities.
OpenAI’s coordinated vulnerability disclosure policy encourages good-faith researchers to report security flaws and provides a formal bug bounty process.
Read: Anthropic Blocks Claude Users Over Biological Misuse Risk
Hacktron said AI tools significantly shortened work that once required larger teams and longer research cycles.
The episode therefore demonstrates AI-assisted cybersecurity capability, but it does not show that Claude or GPT-5.6 Sol independently breached OpenAI without human researchers directing the process.