A harmless pull request inside OpenAI’s internal code repository might be the clearest signal yet that AI is fundamentally changing the pace of security research. Not because an AI went rogue, but because three human researchers used Claude to compress what might have taken weeks into less than three days.
Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, researchers at cybersecurity firm Hacktron AI, reported chaining two separate vulnerabilities to demonstrate access to OpenAI employee ChatGPT and Codex accounts, and eventually to an internal OpenAI GitHub repository. OpenAI fixed the issues and paid out a $6,500 bug bounty. The whole thing, from initial exploit to confirmed access, took under 72 hours.
The entry point was surprisingly mundane. OpenAI’s public community forum runs on Discourse, and the researchers started by looking at how the platform processed HEIC and HEIF image files. That led them to libheif, an open-source image-processing library. They found a vulnerability in how the library handled certain HEIF files and eventually turned it into remote code execution on the server. Standard security research, at first glance.
But Claude changed the speed of what came next. The team initially worked with Claude Opus 4.8 to develop an exploit, but the model couldn’t produce a reliable one against the security protections in their local environment. When Claude Opus 5 became available, they tried again. This time, the model produced a working exploit within hours. The researchers then worked with Claude to adapt it to OpenAI’s specific technical environment. That combination shortened the research cycle dramatically.
From there, the researchers identified a weakness in OpenAI’s single sign-on system and chained it with the forum vulnerability. One flaw opened a path into the Discourse environment; the authentication weakness created a route toward active OpenAI accounts. Once inside, they used an affected Codex account, which had access to OpenAI’s GitHub organisation, to create a harmless pull request in OpenAI’s internal monorepository. They labeled it PR #1186742 and stopped. The point was proof, not theft.
It’s worth being precise about what Claude did and didn’t do here. Claude did not independently attack anything. Human researchers decided what to investigate, interpreted findings, and controlled every action taken. Claude helped write and adapt exploit code, worked through technical problems, and accelerated steps that would otherwise have required significantly more time. That’s a meaningful distinction, but it doesn’t make the result any less significant for security teams watching this space.
The broader implications extend well past OpenAI. The libheif library appears across a wide range of software stacks. Any organization accepting user-uploaded HEIC or HEIF images needs to understand exactly how those files are processed and whether the underlying libraries are patched. A vulnerability in a component that seems peripheral can become the starting point for something much more serious.
Hacktron’s full HEIF Heist research project involved three researchers over roughly two months and cost less than $3,000 in AI token usage. Compare that to the resources traditionally required for research of this depth. Security teams at companies building AI systems, cloud platforms, or automated software environments are now operating in an environment where a small, skilled team with access to a capable AI model can move at a speed that was simply not possible before. That changes the math on how quickly vulnerabilities need to be found and fixed, and by whom.
- Entry point: HEIF image upload vulnerability in OpenAI’s Discourse-based community forum
- AI used: Claude Opus 4.8 initially, then Claude Opus 5 for working exploit development
- Attack chain: libheif remote code execution plus OpenAI SSO authentication weakness
- Proof of access: harmless pull request created in OpenAI’s internal monorepository
- Resolution: OpenAI patched its side the same day; Discourse received a separate fix via HackerOne
- Bounty awarded: $6,500 for the OpenAI-side finding
For AI companies specifically, this is a pointed reminder. The same organizations building advanced AI models are also running standard web infrastructure with standard vulnerabilities. And the tools they’re building are now being used to find those vulnerabilities faster than ever before.



