
Discourse
SoftwareWikipedia
41
MENTIONS
14
EPISODES
14
PODCASTS
Search complete. 41 mentions across 14 episodes found for "Discourse".
Sep 24, 2026
Gemini Escaped Its Test and Started Hacking Real Companies
C
25:00Chris TarbellHOST
Hacking OpenAI.
C
25:02Chris TarbellHOST
Authorized bug bounty research by Hacktron AI chained a heap buffer overflow in Discourse's HEIF image pipeline.
C
25:14Chris TarbellHOST
Right.
C
25:15Chris TarbellHOST
With an OpenAI SSO misconfiguration, the timeline from the first phone to find the retro proof was under 17, under 72 hours.
H
26:05Hector MonsegurHOST
Um, and so same thing kind of happened here.
H
26:08Hector MonsegurHOST
So here's what happens.
H
26:10Hector MonsegurHOST
So you have this forum called Discourse.
H
26:13Hector MonsegurHOST
And on those forums, you can upload images or avatars for your profile, for your character.
Risky Business #854 -- We're Jevpilled
J
7:57James WilsonHOST
Uh, these three, uh, cyber bros from Ha- Hacktron, I think they're called.
J
8:01James WilsonHOST
They, they were doing basically research into image parsing, in particular the HEIF format, and they were basically going round to a bunch of sites and seeing, you know, if we upload these specially crafted image files, where's the parser running, and, and is it vulnerable to s- some of the attack classes they'd found here? And one of the th- uh, things they tested this on was a, uh, forum software called Discourse.
J
8:21James WilsonHOST
And, uh, sure enough, they found that Discourse has a bug where all other images that you upload are parsed by the, uh, I think the FastImage library.
J
8:29James WilsonHOST
But for some reason, if you upload an HEIF, it's parsed by ImageMagick, which uses LibHEIF, which has the bugs and vulnerabilities they were found- they were testing for.
J
8:39James WilsonHOST
Who runs Discourse to run their forums? None other than OpenAI.
J
8:42James WilsonHOST
So they deploy...
J
8:43James WilsonHOST
They basically use these vulnerabilities to, uh, pop remote code execution in OpenAI's forum instance of, uh, their Discourse forum, and were able to exfiltrate tokens.
J
8:53James WilsonHOST
Okay, so-
Security Now 1097: Mega Patch Tuesday Fallout
S
107:49Steve GibsonHOST
OpenAI confirmed a fix about 14 hours after the report, according to Hacktron, and on September 1st paid the team a $6,500 bounty.
S
108:01Steve GibsonHOST
OpenAI said the award, quote, 'recognizes the OpenAI side-finding, not the actions against Discourse,' which is the open source software that runs the forum.
S
108:14Steve GibsonHOST
Testing the forum itself was-"
L
108:15Leo LaporteHOST
That's the ones we use, by the way.
S
110:38Steve GibsonHOST
Any first or third-party service using the same sign-on could have granted the same access.
S
110:45Steve GibsonHOST
The way in was an image bug.
S
110:49Steve GibsonHOST
The forum runs on Discourse, and Discourse passes uploaded, uh, H-E-I-C and H-E-I-F, often verbalized as HEIF images, to a tool called ImageMagick, very popular- Oh, yeah ... uh, image rendering tool, which uses the LibHEIF library to read them.
S
111:13Steve GibsonHOST
A flaw in Live Heap, L- uh, LibHEIF let a specially crafted image- Uh ... corrupt the forum server's memory.
SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers
S
111:13Steve GibsonHOST
a flaw in live heap a live heath let a specially crafted image corrupt the forum server's memory Now, here's where it gets cool, Leo.
S
111:26Steve GibsonHOST
Discourse's advisory rates the result as remote code execution, scores it 8.8 out of 10, and tracks it as CVE, no, 2026, 32, 882.
S
111:40Steve GibsonHOST
So Discourse should be updated, everybody, in order to get rid of this live HEAF exploit, which is now known publicly.
S
111:49Steve GibsonHOST
The public record for the flaw itself is narrower.
S
111:53Steve GibsonHOST
In Leibhief's own advisory and in national vulnerability databases, that CVE ending in 32882 is an out-of-bounds read that can crash the software or leak nearby memory, not a direct code execution bug.
Episode 419 - Claude hacks OpenAI, Google's latest leak, and big tech exits
A
1:48AmitHOST
You would think so, but, uh, the vulnerability was actually in a third-party service.
A
1:54AmitHOST
OpenAI uses Discourse to host their community forums.
A
1:57AmitHOST
The Hacktron team found a severe flaw in how the Discourse system processes HEIF image files.
Y
2:04YuvalHOST
Oh, so it was an image parsing bug.
Y
2:07YuvalHOST
I remember those being a huge headache for mobile operating systems a few years back.
A
2:18AmitHOST
And the timeline they operated on is just fascinating.
A
2:22AmitHOST
Hacktron noted that Claude Opus 5 launched on the evening of July 24th.
A
2:27AmitHOST
By 10:00 AM the very next morning, they had used it to achieve remote code execution on the Discourse cloud.
One Image to Root Them All - The 443 Podcast - Episode 388
C
8:01Corey NachreinerHOST
for sure.
M
8:03Marc LaliberteHOST
So moving on, though, found another really interesting research post from the folks over at Hacktron, where they posted a write-up of a vulnerability report that they sent to OpenAI, as well as the forum software company Discourse.
M
8:21Marc LaliberteHOST
They said while trying to find critical security vulnerabilities in different frontier AI companies, they discovered a single sign-on misconfiguration in OpenAI's identity infrastructure and a new remote code execution vulnerability in Discourse, which allowed them to take over the account of basically any OpenAI user, including OpenAI employees.
M
8:43Marc LaliberteHOST
that participated in their community forums.
M
8:46Marc LaliberteHOST
So basically, OpenAI allows you to sign into their community forums using your OpenAI account.
C
9:11Corey NachreinerHOST
repositories, for example.
M
9:14Marc LaliberteHOST
So this post is interesting.
M
9:16Marc LaliberteHOST
It walks through their analysis, really focusing on the image upload pipeline for this forum software, Discourse.
Cyber Security News for September 21 2026 - Daily DefSec Brief
J
2:12Jerry BellHOST
The fix shipped Thursday, so time to upgrade.
J
2:15Jerry BellHOST
Six, a crafted HEIC photo upload was enough to run code or leak memory on Slack, Meta, Discourse, and GitHub Enterprise Server.
J
2:24Jerry BellHOST
through libheif, the decoder that ImageMagick and a lot of other image tools use for those files.
J
2:30Jerry BellHOST
On Discourse and GitHub, the uploader had to be logged in.
J
2:34Jerry BellHOST
On OpenAI's own forum, the same bug plus a login flaw got researchers into staff ChatGPT accounts.
J
2:41Jerry BellHOST
No attacks are reported yet.
Is Obsolescence Planned, or is It Natural? - DTNS 5356
T
3:30Tom MerrittHOST
They didn't do it, but they said, we saw that we could have had access.
T
3:34Tom MerrittHOST
One flaw they used was in an unpatched version of ImageMagick being used by a third-party message board called Discourse, which they chained to another flaw in OpenAI's own software.
T
3:45Tom MerrittHOST
They alerted Discourse, Discourse patched its flaw on July 27th, and OpenAI paid the team $6,500 for finding the bug in the OpenAI software.
S
3:55Sarah LaneHOST
Ooh, what are you going to do with all that money? I
T
3:57Tom MerrittHOST
don't know.
Is Obsolescence Planned, or is It Natural? – DTNS 5356
T
3:29Tom MerrittHOST
They didn't do it, but they said, we saw that we could have had access.
T
3:34Tom MerrittHOST
One flaw they used was, was in an unpatched version of ImageMagick being used by a third-party message board called Discourse, which they chained to another flaw in OpenAI's own software.
T
3:45Tom MerrittHOST
They alerted Discourse, Discourse patched its flaw on July 27th, and OpenAI paid the team $6,500 for finding the bug in the OpenAI software.
S
3:55Sarah LaneHOST
Ooh, what are you going to do with all that money? I
T
3:57Tom MerrittHOST
don't know.
Is Obsolescence Planned, or is It Natural? - DTNS 5356
T
3:29Tom MerrittHOST
They didn't do it, but they said, we saw that we could have had access.
T
3:34Tom MerrittHOST
One flaw they used... was in an unpatched version of ImageMagick being used by a third-party message board called Discourse, which they chained to another flaw in OpenAI's own software.
T
3:45Tom MerrittHOST
They alerted Discourse, Discourse patched its flaw on July 27th, and OpenAI paid the team $6,500 for finding the bug in the OpenAI software.
S
3:55Sarah LaneHOST
Ooh, what are you going to do with all
M
3:56Molly WoodGUEST
that money? I
4 more episodes mention Discourse.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.