Discourse HEIC/HEIF remote code execution flaw
Vulnerability
Summary
Hide ▲
Show ▼
Researchers confirmed remote code execution through Discourse HEIC/HEIF uploads by exploiting an unpatched libheif flaw in the image-decoding path. The weakness affected Discourse deployments that forwarded unsupported HEIC/HEIF images to ImageMagick for decoding. The bug had been fixed upstream a year earlier, but it had not been treated as a security issue and lacked a CVE. That left exposed services vulnerable until the later fix and sandboxing changes.
Related Happenings
Zoom annotation tool flaws (multiple vulnerabilities)
Vulnerability
H score24
First: 11.08.2026 22:08
Last: 11.08.2026 22:08
Sources 1
About this happening:
Zoom's annotation tool flaws could let one meeting participant compromise another attendee's client across supported Zoom Workplace, Zoom Workplace VDI Client for Wi...
Zoom annotation tool flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Zoom's annotation tool flaws could let one meeting participant compromise another attendee's client across supported Zoom Workplace, Zoom Workplace VDI Client for Wi...
Bing image search SVG command injection (multiple vulnerabilities)
Vulnerability
H score41
First: 24.07.2026 14:45
Last: 24.07.2026 14:45
Sources 1
About this happening:
A crafted SVG in Bing image search triggered OS command injection in Bing image-processing workers, causing code execution as NT AUTHORITY\SYSTEM on Windows an...
Bing image search SVG command injection (multiple vulnerabilities)
VulnerabilityAbout this happening: A crafted SVG in Bing image search triggered OS command injection in Bing image-processing workers, causing code execution as NT AUTHORITY\SYSTEM on Windows an...
Timeline
-
18.09.2026 15:45 2 articles · 2h ago
Hacktron reports remote code execution in Discourse HEIC/HEIF upload path
Initial DisclosureHacktron says it built a working exploit for an unpatched libheif flaw in OpenAI's community.openai.com Discourse instance, using Claude Opus 4.8 and Opus 5 to turn unsupported HEIC/HEIF uploads passed through ImageMagick into remote code execution. The firm reported the libheif flaw to Discourse through HackerOne; Discourse had a fix ready within two days, added image-processing sandboxing, and published a security advisory.
Show sources
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code — www.securityweek.com — 18.09.2026 15:45