ChatGPT Flaw Exposed: Prompt Injection Bypasses File Access Limits
A recent disclosure by security researcher zer0dac highlights a vulnerability in ChatGPT, which could allow attackers to circumvent file access controls through prompt injection and path traversal. OpenAI has since implemented fixes to address the reported issue.
The flaw centers on how ChatGPT processes uploaded documents. Typically, the platform restricts direct downloads of original files, responding with a message that such content is temporary and cannot be extracted.

zer0dac identified a workaround during testing: by asking ChatGPT to edit an uploaded file and then requesting a download link under the pretense of accidental deletion, users can generate a valid URL. This link not only exposes internal retrieval paths but also enables path traversal attacks to access files outside the intended directory.
While the existing sandbox limits direct access to highly sensitive data, this vulnerability could serve as a critical step in broader attack chains. OpenAI has responded by refining the logic for generating download URLs, effectively mitigating the risk of internal path exposure. This case underscores the importance of rigorous input filtering and strict permission isolation in securing large language model applications.
Related article
4 Days Left to Save Up to $190 on TechCrunch Founder Summit 2026
Founders don’t grow in isolation. The most successful founders learn from peers navigating similar hurdles, gain wisdom from operators who have already scaled, and build relationships with investors who can fuel the next stage of growth.You have just
Google to Sunset Gemini 3 Pro Preview, Mandates Developer Migration
Google has issued a critical update on its developer forum, confirming that the Gemini3Pro Preview service within the Gemini API and AI Studio will be discontinued effective March 9, 2026. To maintain operational stability, Google advises all develop
Claude Code Official Voice Mode Launches: Press Space to Speak, Boosting AI Programming Efficiency
Anthropic’s AI coding assistant, Claude Code, has been significantly upgraded with the official introduction of voice mode. This new capability empowers developers to move beyond keyboard-only interactions, enabling them to issue commands via natural
Related Special Topic Recommendations
Comments (0)
0/500
A recent disclosure by security researcher zer0dac highlights a vulnerability in ChatGPT, which could allow attackers to circumvent file access controls through prompt injection and path traversal. OpenAI has since implemented fixes to address the reported issue.
The flaw centers on how ChatGPT processes uploaded documents. Typically, the platform restricts direct downloads of original files, responding with a message that such content is temporary and cannot be extracted.

zer0dac identified a workaround during testing: by asking ChatGPT to edit an uploaded file and then requesting a download link under the pretense of accidental deletion, users can generate a valid URL. This link not only exposes internal retrieval paths but also enables path traversal attacks to access files outside the intended directory.
While the existing sandbox limits direct access to highly sensitive data, this vulnerability could serve as a critical step in broader attack chains. OpenAI has responded by refining the logic for generating download URLs, effectively mitigating the risk of internal path exposure. This case underscores the importance of rigorous input filtering and strict permission isolation in securing large language model applications.
4 Days Left to Save Up to $190 on TechCrunch Founder Summit 2026
Founders don’t grow in isolation. The most successful founders learn from peers navigating similar hurdles, gain wisdom from operators who have already scaled, and build relationships with investors who can fuel the next stage of growth.You have just
Google to Sunset Gemini 3 Pro Preview, Mandates Developer Migration
Google has issued a critical update on its developer forum, confirming that the Gemini3Pro Preview service within the Gemini API and AI Studio will be discontinued effective March 9, 2026. To maintain operational stability, Google advises all develop
Claude Code Official Voice Mode Launches: Press Space to Speak, Boosting AI Programming Efficiency
Anthropic’s AI coding assistant, Claude Code, has been significantly upgraded with the official introduction of voice mode. This new capability empowers developers to move beyond keyboard-only interactions, enabling them to issue commands via natural





Home






