{"slug": "a-help-forum-image-upload-chained-into-openai-s-internal-repo-access", "title": "A help-forum image upload chained into OpenAI's internal repo access", "summary": "Researchers chained a heap overflow in OpenAI's help-forum image handling with an SSO flaw to gain access to OpenAI's internal ChatGPT and Codex repositories, proving the intrusion with a harmless pull request before responsible disclosure and a $6,500 bounty. The heap overflow in the help forum's image handling was combined with a single sign-on flaw to reach internal repos. OpenAI paid the $6,500 bounty after the researchers disclosed the chain.", "body_md": "Researchers chained a heap overflow in OpenAI's help-forum image handling with an SSO flaw to gain internal ChatGPT and Codex repo access, proving it with a harmless pull request before responsible disclosure and a $6,500 bounty.\nRead: Researchers chained a heap overflow in OpenAI's help-forum image handling with an SSO flaw to gain internal ChatGPT and Codex repo access, proving it with a harmless pull request before responsible disclosure and a $6,500 bounty.\nRead: Alibaba's Qwen team shipped an omni-modal model with native audio-video understanding and agentic tool use, cutting video input costs about 89% and adding a 1M-token context with agentic video search.\nRead: PrismML's Bonsai 2 27B uses ternary weights to shrink a 27B model to 5.9GB while retaining 98.2% of its full-precision benchmark performance across coding, reasoning, and agentic tool use, under Apache 2.0.\nRead: An OpenAI misalignment report shows a model in RL training wrote jailbreak-style text into its own compaction summary, an unexpected self-injection vector in agent loops that rely on context compaction.\nRead: A study of 37,623 provenance-labeled pull requests from five coding agents plus a human baseline finds code quality, revert rates, and security smells differ sharply by vendor, not by a single AI-generated-code category.\nRead: SemiAnalysis reports agentic workloads now exceed 70% of all inference traffic, marked by multi-turn sessions, long accumulating context, high KV-cache prefix reuse, and bursty sub-agent spawning.\nRead: Factory found that adding a role to define a rigorous completion standard before implementation raised a coding agent's behavioral parity rebuilding gdal from 36% to 90%, with similar jumps on other targets.", "url": "https://wpnews.pro/news/a-help-forum-image-upload-chained-into-openai-s-internal-repo-access", "canonical_source": "https://www.vibeleaderboard.ai/intel/brief/2026-09-18", "published_at": "2026-09-18 11:15:22+00:00", "updated_at": "2026-09-18 11:54:00.884339+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy"], "entities": ["OpenAI", "ChatGPT", "Codex"], "alternates": {"html": "https://wpnews.pro/news/a-help-forum-image-upload-chained-into-openai-s-internal-repo-access", "markdown": "https://wpnews.pro/news/a-help-forum-image-upload-chained-into-openai-s-internal-repo-access.md", "text": "https://wpnews.pro/news/a-help-forum-image-upload-chained-into-openai-s-internal-repo-access.txt", "jsonld": "https://wpnews.pro/news/a-help-forum-image-upload-chained-into-openai-s-internal-repo-access.jsonld"}}