logo

Pen testers accused of 'blackmail' after reporting Eurostar chatbot flaws

ID: 70bdcd11-2bdc-5797-9df7-8190cfef219a

STIX ID: report--70bdcd11-2bdc-5797-9df7-8190cfef219a

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2025-12-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Pen Test Partners found multiple security flaws in Eurostar's public AI chatbot — notably prompt injection, HTML injection, and absent verification of conversation/message IDs — that could expose system prompts, enable phishing links or stored XSS; Eurostar reportedly patched some issues after a delayed and problematic disclosure process.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.