Security researchers exploit openai's ChatGPT accounts via anthropic's claude
On September 18, The Wall Street Journal reported that security researchers from Hacktron AI successfully breached an OpenAI employee's ChatGPT account using Anthropic's Claude, gaining access to the company's private software code repository. The breach occurred on July 23 when the team discovered a vulnerability in Discourse's handling of image files. They used a special version of Claude Opus 4.8 to exploit the flaw, which failed initially. The next day, after Anthropic released Opus 5, the team successfully exploited the updated version.
The vulnerability, labeled CVE-2026-45788, is an unrestricted upload flaw in Discourse's secure upload feature. Attackers could access protected content without authentication. Discourse was notified on July 25 and fixed the issue the same day. The researchers accessed the Discourse server hosting OpenAI's forum and obtained login tokens, which were valid for ChatGPT and OpenAI's GitHub service. They accessed the Monorepo, a repository containing algorithm secrets for faster and more efficient models, but stopped after realizing they had access to sensitive data.
Mohan Pedhapati, CTO of Hacktron AI, stated that the attack highlights the real threat posed by state-sponsored cyber teams: 'I don't think we are smarter than foreign threats. We are just three people with Claude and Codex subscriptions.'