ThreatPaper
False

OpenAI authorized the live exploitation of its own forum as part of this bug bounty research

Assessment

OpenAI's own comment, published within Hacktron's disclosure timeline, states that testing against the Discourse-hosted community.openai.com "was explicitly excluded from our bug bounty program," and that the $6,500 award recognized only the OpenAI-side SSO finding, not the actions taken against the Discourse-hosted forum itself. The researchers separately reported the forum RCE to Discourse through HackerOne, not through OpenAI's program.

Where this claim appeared

OpenAI (via Hacktron AI's published disclosure timeline) · 2026-09-13

https://www.hacktron.ai/blog/hacking-openai

What “False” means

Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.

1 of 5 · rating scale

Assessed in

Hacktron used Claude to hack OpenAI's forum, take over an employee's Codex, and open a PR in OpenAI's own repo

Think this assessment is wrong? Report an error.