Security Flaws Found in Every Script Generated by ChatGPT, Copilot, and Gemini
ID: de4d324d-9bd5-5d9a-ae08-3904ed7daa08
STIX ID: report--de4d324d-9bd5-5d9a-ae08-3904ed7daa08
Feed Name: cybersecurityNews.com
An academic study found that every automation script produced by ChatGPT, Microsoft Copilot, and Google Gemini contained exploitable vulnerabilities — including SSRF, path traversal, template and email header injection, symlink issues, and overly broad exception handling. Researchers generated nine Python scripts from identical prompts, used an automated review to identify 45 findings condensed into 17 vulnerability classes, scored them with CVSS 3.1, mapped them to OWASP and MITRE ATT&CK, and recommend mandatory code reviews, restricted execution permissions, prioritized remediation, and developer education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
