Researchers Use Claude to Access OpenAI’s Internal Code Repository
OpenAI’s community forum runs on Discourse and used single sign-on to connect users with ChatGPT and Codex, which in turn could reach services such as GitHub. Hacktron AI’s research shows how a flaw in third-party infrastructure can cascade through federated identity into privileged developer systems. The case also highlights how advanced AI agents are lowering the cost and time needed to turn memory-corruption bugs into working exploits, raising new questions about access controls and oversight.
Hacktron AI researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini began reviewing Discourse’s image pipeline on July 23, 2026. They used Anthropic’s Claude Opus 4.8 and, after its July 24 release, Claude Opus 5 to exploit a libheif heap overflow, compromise OpenAI employee accounts and reach an internal GitHub monorepo in under 72 hours. They said they did not inspect proprietary code, instead directing Codex to open harmless pull request No. 1186742. OpenAI confirmed a fix on July 25, about 14 hours after the Bugcrowd submission, and awarded the team $6,500 on Sept. 1.
All Coverage
1 original reportsThe Backstory
The history behind this eventResearchers Use Anthropic’s Claude to Breach OpenAI
Advanced language models are reshaping cybersecurity by helping researchers find software flaws, develop exploits and connect vulnerabilities across systems. The Hacktron AI case is significant because a weakness in third-party forum infrastructure became a route into employee AI accounts and connected developer tools. It highlights the expanding risk created when AI agents hold credentials or integrations spanning source-code repositories, communications and other sensitive corporate services.
Hacktron AI said its researchers used Anthropic’s Claude Opus 4.8 and Opus 5 to chain a libheif image-processing flaw with an OpenAI single sign-on weakness on July 25, 2026. In less than 72 hours, they compromised multiple employee ChatGPT and Codex accounts and demonstrated internal repository access through a harmless pull request, PR #1186742, without reviewing sensitive code. OpenAI confirmed a fix about 14 hours after the Bugcrowd submission and awarded $6,500 on Sept. 1.
Anthropic Patches Claude Code GitHub Actions Flaw to Reduce Token-Leak Risk
Claude Code GitHub Actions allows AI agents to respond to instructions and modify code within software-development workflows. If trigger identities and permissions are not rigorously checked, attackers could use malicious content to induce an agent to access sensitive information such as GitHub tokens. That could compromise code repositories and automated deployment environments, making the patch important for software supply-chain security.
Anthropic patched a permission bypass in Claude Code v1.0.94 caused by insufficient checks on GitHub App triggers. It also strengthened configuration controls and safeguards to reduce the risk of token leaks. Available information did not disclose the exact dates of the vulnerability advisory or patch, the number of affected organizations, any financial losses or known cases of exploitation.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →