Tech & AI News
Hacker News

Hacking OpenAI

HacktronAI exposed two critical vulnerabilities that allowed remote code execution and administrative access to OpenAI’s community forum, enabling compromise of multiple ChatGPT accounts. Within 72 hours, the team accessed internal OpenAI repositories, created a proof-of-concept pull request, and reported the findings through Bugcrowd and HackerOne, receiving a $6,500 bounty. The vulnerabilities involved an SSO misconfiguration and a libheif RCE affecting the forum’s image-processing library.