logo

ChatGPT File Download Flow Vulnerability Could Be Abused to Access System Files

ID: 919c0bba-aebf-56d2-90d0-8b8a0b357aa5

STIX ID: report--919c0bba-aebf-56d2-90d0-8b8a0b357aa5

Feed Name: cybersecurityNews.com

Threat Score
35/100

Date Published: 2026-07-02

Date Updated: 2026-07-02

Author: Guru Baran

...
...

A researcher demonstrated a proof-of-concept chain in ChatGPT where social-engineering the model caused it to generate a download URL with a sandbox_path parameter that, due to inconsistent path normalization, allowed traversal (e.g., /mnt/data/test.html/../../../../etc/passwd) and returned /etc/passwd from the execution environment. OpenAI has remediated the issue by redesigning the download flow; the practical impact was limited by sandboxing, but the case highlights how prompt-based guardrail manipulation and traditional web vulnerabilities can combine in LLM platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.