buildOne report1 publisher Hacktron chained a heap overflow in libheif to an OpenAI SSO flaw and opened a pull request in OpenAI's internal monorepo in under 72 hours. The bug had been fixed upstream a year earlier, but the fix never reached Debian's packages.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives50
- Confidence40
The libheif bug was fixed upstream a year earlier without a security label or a CVE, so a Discourse image check that ignored HEIC left it reachable, and forum sign-in tokens carried full API access to the accounts behind them.
Perspective Coverage
6 publishers
- Builder
- Builder 35%
- Operator
- Operator 55%
- Investor
- Investor 10%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence66
CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence68
The image parsing bug had been fixed upstream about a year earlier, and the decision not to ship that fix belonged to Discourse. OpenAI's forum shared single sign-on with internal systems, so a forum account became GitHub access.
Perspective Coverage
9 publishers
- Builder
- Builder 35%
- Operator
- Operator 39%
- Investor
- Investor 26%
Reality
- Evidence70
- Adoption63
- Hype gap+28
- Incentives60
- Confidence62
buildOne report1 publisher An open-source gateway author walked Hacktron's five-step path into OpenAI through his own seven detection layers. The first two hops are requests to a forum and an identity provider. Where the gateway is deployed decides what any of it can read.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+60
- Incentives80
- Confidence45
buildOne report1 publisher Hacktron's report puts the vulnerable code in libheif, two dependency steps below an ImageMagick call on OpenAI's Discourse forum, and says the upstream fix never went through the usual security advisory process.
Reality
- Evidence38
- Adoption28
- Hype gap+15
- Incentives55
- Confidence42
buildOne report1 publisher Hacktron's path into OpenAI's internal repos ran through a libheif bug Debian had not backported and a single sign-on flow that trusted community.openai.com. The dev.to breakdown says the model changed what the attack cost. The category of attack was the same either way.
Reality
- Evidence66
- Adoption72
- Hype gap−12
- Incentives58
- Confidence63
The point release corrects 106 source packages and rebuilds the installer around a 6.12.107+deb13 kernel, so hosts imaged from older trixie media come up on versions predating all 92 advisories and only catch up on the first update run.
Reality
- Evidence62
- Adoption45
- Hype gap−5
- Incentives18
- Confidence66
Rails shipped fixes on July 29 in 7.2.3.2, 8.0.5.1 and 8.1.3.1. Whether your app is actually closed depends on the libvips version sitting on the host and on which features serve a processed image back to the uploader.
Reality
- Evidence71
- Adoption58
- Hype gap−10
- Incentives62
- Confidence66
buildOne report1 publisher Generated images arrive with three metadata layers plus a pixel signal that no metadata tool touches, and whether the signed manifest survives depends on whether anything in your pipeline decodes and writes the file again.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+12
- Incentives70
- Confidence48
buildOne report1 publisher A desktop app that shells out to openssl.exe and ffmpeg.exe can absorb a CVE with a few-megabyte drop-in. The author is unusually clear about the price: spawn latency, and a parser per tool.
Reality
- Evidence30
- Adoption20
- Hype gap+5
- Incentives65
- Confidence48