Researchers discovered a heap buffer overflow vulnerability in the libheif library, which is used by Discourse, the forum software used by OpenAI. They chained this vulnerability with an SSO misconfiguration to gain access to OpenAI's internal repositories. The vulnerability was reported to OpenAI and Discourse, and a patch was released. OpenAI paid a $6,500 bounty for the discovery.