Skip to main content
LIVE SUN, 4 OCT, 2026 BENGALURU · 28°C EDITION № 157 · FREE · NO LOGIN
AI AI · 1 MIN READ

Researchers exploit vulnerabilities to access OpenAI internal repositories

On July 25, 2026, researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini exploited two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts.

On July 25, 2026, researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini exploited two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts. This breach allowed them to access internal OpenAI repositories and other connected systems, according to a detailed report published on hacktron.ai.

The team chained a heap buffer overflow vulnerability in the libheif library with a single sign-on (SSO) misconfiguration to gain unauthorized access. By leveraging these flaws, they bypassed security controls protecting employee accounts and internal data. The researchers documented their findings and the technical steps involved in the exploit in a blog post on hacktron.ai authored by the three security experts.

This incident highlights ongoing security challenges in protecting AI platforms and their internal infrastructure. OpenAI’s repositories contain sensitive code and data critical to its AI models, making such breaches potentially damaging. Similar vulnerabilities in third-party libraries and authentication systems have been exploited in other tech firms, underscoring the importance of rigorous security audits and patch management.

OpenAI has since released patches addressing the affected versions and misconfigurations. The researchers acknowledged the coordinated response and shared technical details to help the community prevent similar attacks. The blog post on hacktron.ai remains a key resource for understanding the exploit and mitigation steps.

Editorial standards. Reported and edited at Startupniti's news desk from the sources listed in the right rail. Every fact traces to a citation. If something looks wrong, write to corrections.
▸ WIRE
Premium content free for first 12 months · sign up to unlock Razorpay subscriptions launch Jan 2027 — ₹199/mo or ₹999/yr Every story reads every Indian tech source so you don't have to Every article cited · trust the source, not just the byline India's startup desk, edited daily Founders · Funding · Policy · Tech — three crawls a day Premium content free for first 12 months · sign up to unlock Razorpay subscriptions launch Jan 2027 — ₹199/mo or ₹999/yr Every story reads every Indian tech source so you don't have to Every article cited · trust the source, not just the byline India's startup desk, edited daily Founders · Funding · Policy · Tech — three crawls a day