Find notable cyber news and cases, enriched with sources, timelines, and signals.

Discourse HEIC/HEIF remote code execution flaw

Vulnerability
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

Researchers confirmed remote code execution through Discourse HEIC/HEIF uploads by exploiting an unpatched libheif flaw in the image-decoding path. The weakness affected Discourse deployments that forwarded unsupported HEIC/HEIF images to ImageMagick for decoding. The bug had been fixed upstream a year earlier, but it had not been treated as a security issue and lacked a CVE. That left exposed services vulnerable until the later fix and sandboxing changes.

Related Happenings

Zoom annotation tool flaws (multiple vulnerabilities)

Vulnerability
H score24 First: 11.08.2026 22:08 Last: 11.08.2026 22:08 Sources 1

About this happening: Zoom's annotation tool flaws could let one meeting participant compromise another attendee's client across supported Zoom Workplace, Zoom Workplace VDI Client for Wi...

Bing image search SVG command injection (multiple vulnerabilities)

Vulnerability
H score41 First: 24.07.2026 14:45 Last: 24.07.2026 14:45 Sources 1

About this happening: A crafted SVG in Bing image search triggered OS command injection in Bing image-processing workers, causing code execution as NT AUTHORITY\SYSTEM on Windows an...

Timeline

  1. 18.09.2026 15:45 2 articles · 2h ago

    Hacktron reports remote code execution in Discourse HEIC/HEIF upload path

    Initial Disclosure

    Hacktron says it built a working exploit for an unpatched libheif flaw in OpenAI's community.openai.com Discourse instance, using Claude Opus 4.8 and Opus 5 to turn unsupported HEIC/HEIF uploads passed through ImageMagick into remote code execution. The firm reported the libheif flaw to Discourse through HackerOne; Discourse had a fix ready within two days, added image-processing sandboxing, and published a security advisory.

    Show sources