跳到正文
北京时间
原文
Rohan Paul· @rohanpaul_ai · X·· 11 天前精选AI 评分76
AI 导读

据 WSJ 报道,三名研究人员使用 Claude Opus 5 将 Discourse 的一个漏洞串联成对 OpenAI 私有代码的访问。 researchers 在 Discourse 服务器上获得了包括 OpenAI 员工在内的认证 token,部分 forum token 可用于 ChatGPT 并触达 OpenAI 的 GitHub 服务。

推荐理由

原文交代了漏洞链如何跨越身份边界以及 OpenAI 的核查结论,读者可以据此评估 AI 辅助安全研究的实际影响范围。

正文 · 原文

WSJ: Three researchers used Claude Opus 5 to chain a Discourse flaw into access to OpenAI’s private code.

That code reached the Discourse server and gave the researchers access to authentication tokens, including tokens belonging to OpenAI employees.

Some forum tokens worked on ChatGPT and could also reach OpenAI’s GitHub service, turning one identity boundary into another.

OpenAI said its review found only “limited reads” of private-repository metadata and code changes; no model weights were believed exposed.

来源:Rohan Paul · x.com