<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef" -->

---
title: OpenAI Hacked with a 1-Year-Old Bug | daily.dev
description: A breakdown of how OpenAI was compromised through a year-old memory corruption bug in Libheif, a HEIF image library used as a dependency by ImageMagick within...
canonical: https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OpenAI Hacked with a 1-Year-Old Bug | daily.dev
og:description: A breakdown of how OpenAI was compromised through a year-old memory corruption bug in Libheif, a HEIF image library used as a dependency by ImageMagick within...
og:url: https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef
og:image: https://api.daily.dev/og/posts/T1sBkW1EF.png
og:image:alt: OpenAI Hacked with a 1-Year-Old Bug
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAI Hacked with a 1-Year-Old Bug

**[LiveOverflow](https://daily.dev/sources/liveoverflow)** · 10 min read · 1 upvotes · 0 comments

## Summary

A breakdown of how OpenAI was compromised through a year-old memory corruption bug in Libheif, a HEIF image library used as a dependency by ImageMagick within Discourse's infrastructure. The vulnerability was fixed upstream in Libheif in mid-2025, but Debian's packaging and release freeze cycles meant the fix never made it into the Debian 12 and Debian 13 base images Discourse relied on, leaving the hole open well into 2026. The piece traces the dependency chain from OpenAI to Discourse to Debian to Libheif, explains how an AI coding agent was prompted to find the suspicious commit, and argues that dependency management, not AI capability, remains the core defensive challenge.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.youtube.com/watch?v=qypnjORyWNI>

## Questions this post answers

### How was OpenAI hacked through a year-old vulnerability if it was already patched?

OpenAI was compromised via Discourse, which used ImageMagick to process images, which in turn relied on Libheif for HEIF parsing. Libheif fixed the underlying memory corruption bug in a May 2025 commit, released in version 1.19.2 in July 2025, but Debian 12 and Debian 13 both shipped older, vulnerable Libheif versions because Debian's package freeze and backport cycles lagged behind, leaving the bug exploitable into 2026.

_daily.dev readers tracking supply chain risk can follow how packaging delays like this expose production systems._

### Why did Debian 13 still ship a vulnerable version of Libheif even after the fix was released?

Debian 13 froze its Libheif package version roughly three to four months before its August 2025 release, before the May 2025 fix had propagated into a Libheif release and before it was flagged as high priority since the fix never received a CVE. A proper backport for Debian 13 only arrived in August 2026, a year after the original fix and too late to prevent the OpenAI breach.

_developers relying on distro-packaged libraries can use daily.dev to stay ahead of these packaging lag risks._

### Why did Discourse's HEIF image handling end up vulnerable to this Libheif bug?

Discourse used FastImage to validate most image formats before passing them to ImageMagick, but HEIF images were passed directly into ImageMagick without that check, making the Libheif dependency reachable and exploitable. Discourse's fix was to stop relying on the Debian-packaged Libheif entirely and instead install and maintain a specific, deliberately updated version themselves.

_teams hardening image upload pipelines can track dependency-handling practices like this through daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OpenAI Hacked with a 1-Year-Old Bug","url":"https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef"},"datePublished":"2026-10-02T14:37:40.750Z","dateModified":"2026-10-02T14:38:01.270Z","description":"A breakdown of how OpenAI was compromised through a year-old memory corruption bug in Libheif, a HEIF image library used as a dependency by ImageMagick within...","image":"https://i.ytimg.com/vi/qypnjORyWNI/sddefault.jpg","thumbnailUrl":"https://i.ytimg.com/vi/qypnjORyWNI/sddefault.jpg","isAccessibleForFree":true,"articleSection":"LiveOverflow","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"LiveOverflow","logo":"https://media.daily.dev/image/upload/s--UcWYLZRF--/f_auto/v1728073040/logos/liveoverflow","url":"https://daily.dev/sources/liveoverflow"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,vulnerability","timeRequired":"PT10M","video":{"@type":"VideoObject","name":"OpenAI Hacked with a 1-Year-Old Bug","description":"A breakdown of how OpenAI was compromised through a year-old memory corruption bug in Libheif, a HEIF image library used as a dependency by ImageMagick within...","thumbnailUrl":"https://i.ytimg.com/vi/qypnjORyWNI/sddefault.jpg","uploadDate":"2026-10-02T14:37:40.750Z","duration":"PT10M","url":"https://api.daily.dev/r/T1sBkW1EF","embedUrl":"https://www.youtube.com/embed/qypnjORyWNI"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"LiveOverflow","item":"https://daily.dev/sources/liveoverflow"},{"@type":"ListItem","position":3,"name":"OpenAI Hacked with a 1-Year-Old Bug"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/openai-hacked-with-a-1-year-old-bug-t1sbkw1ef#faq","mainEntity":[{"@type":"Question","name":"How was OpenAI hacked through a year-old vulnerability if it was already patched?","acceptedAnswer":{"@type":"Answer","text":"OpenAI was compromised via Discourse, which used ImageMagick to process images, which in turn relied on Libheif for HEIF parsing. Libheif fixed the underlying memory corruption bug in a May 2025 commit, released in version 1.19.2 in July 2025, but Debian 12 and Debian 13 both shipped older, vulnerable Libheif versions because Debian's package freeze and backport cycles lagged behind, leaving the bug exploitable into 2026. daily.dev readers tracking supply chain risk can follow how packaging delays like this expose production systems."}},{"@type":"Question","name":"Why did Debian 13 still ship a vulnerable version of Libheif even after the fix was released?","acceptedAnswer":{"@type":"Answer","text":"Debian 13 froze its Libheif package version roughly three to four months before its August 2025 release, before the May 2025 fix had propagated into a Libheif release and before it was flagged as high priority since the fix never received a CVE. A proper backport for Debian 13 only arrived in August 2026, a year after the original fix and too late to prevent the OpenAI breach. developers relying on distro-packaged libraries can use daily.dev to stay ahead of these packaging lag risks."}},{"@type":"Question","name":"Why did Discourse's HEIF image handling end up vulnerable to this Libheif bug?","acceptedAnswer":{"@type":"Answer","text":"Discourse used FastImage to validate most image formats before passing them to ImageMagick, but HEIF images were passed directly into ImageMagick without that check, making the Libheif dependency reachable and exploitable. Discourse's fix was to stop relying on the Debian-packaged Libheif entirely and instead install and maintain a specific, deliberately updated version themselves. teams hardening image upload pipelines can track dependency-handling practices like this through daily.dev."}}]}
```

