option
Home
Flash News
Content
PaulHill
PaulHill
July 7, 2026

Security researcher zer0dac disclosed a ChatGPT vulnerability allowing attackers to bypass file access restrictions via prompt injection and path traversal, gaining unauthorized data. The flaw: after uploading a file, users could trick ChatGPT into editing it and then request a download link by claiming accidental deletion, generating a valid URL. This enabled internal path exposure and further traversal attempts. OpenAI fixed the mechanism by adjusting download URL generation logic after receiving the report, eliminating internal file path risks. The bug could not directly obtain highly sensitive data due to sandboxing but could be part of a complex attack chain.

Security researcher zer0dac disclosed a ChatGPT vulnerability allowing attackers to bypass file access restrictions via prompt injection and path traversal, gaining unauthorized data. The flaw: after uploading a file, users could trick ChatGPT into editing it and then request a download link by claiming accidental deletion, generating a valid URL. This enabled internal path exposure and further traversal attempts. OpenAI fixed the mechanism by adjusting download URL generation logic after receiving the report, eliminating internal file path risks. The bug could not directly obtain highly sensitive data due to sandboxing but could be part of a complex attack chain.
Comments (0)
0/300
OR