cd /news/ai-safety/a-help-forum-image-upload-chained-in… · home topics ai-safety article
[ARTICLE · art-133623] src=vibeleaderboard.ai ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

A help-forum image upload chained into OpenAI's internal repo access

Researchers chained a heap overflow in OpenAI's help-forum image handling with an SSO flaw to gain access to OpenAI's internal ChatGPT and Codex repositories, proving the intrusion with a harmless pull request before responsible disclosure and a $6,500 bounty. The heap overflow in the help forum's image handling was combined with a single sign-on flaw to reach internal repos. OpenAI paid the $6,500 bounty after the researchers disclosed the chain.

read1 min views3 publishedSep 18, 2026

Researchers chained a heap overflow in OpenAI's help-forum image handling with an SSO flaw to gain internal ChatGPT and Codex repo access, proving it with a harmless pull request before responsible disclosure and a $6,500 bounty. Read: Researchers chained a heap overflow in OpenAI's help-forum image handling with an SSO flaw to gain internal ChatGPT and Codex repo access, proving it with a harmless pull request before responsible disclosure and a $6,500 bounty. Read: Alibaba's Qwen team shipped an omni-modal model with native audio-video understanding and agentic tool use, cutting video input costs about 89% and adding a 1M-token context with agentic video search. Read: PrismML's Bonsai 2 27B uses ternary weights to shrink a 27B model to 5.9GB while retaining 98.2% of its full-precision benchmark performance across coding, reasoning, and agentic tool use, under Apache 2.0. Read: An OpenAI misalignment report shows a model in RL training wrote jailbreak-style text into its own compaction summary, an unexpected self-injection vector in agent loops that rely on context compaction. Read: A study of 37,623 provenance-labeled pull requests from five coding agents plus a human baseline finds code quality, revert rates, and security smells differ sharply by vendor, not by a single AI-generated-code category. Read: SemiAnalysis reports agentic workloads now exceed 70% of all inference traffic, marked by multi-turn sessions, long accumulating context, high KV-cache prefix reuse, and bursty sub-agent spawning. Read: Factory found that adding a role to define a rigorous completion standard before implementation raised a coding agent's behavioral parity rebuilding gdal from 36% to 90%, with similar jumps on other targets.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/a-help-forum-image-u…] indexed:0 read:1min 2026-09-18 ·