logo

ChatGPT SSRF bug quickly becomes a favorite attack vector

ID: 97d02e23-484d-5190-9389-bc9f4a02f9f4

STIX ID: report--97d02e23-484d-5190-9389-bc9f4a02f9f4

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2025-03-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Active SSRF exploitation (CVE-2024-27564) in ChatGPT's pictureproxy.php** — Threat actors are exploiting a medium-severity SSRF (CVSS 6.5) that allows unauthenticated injection of URLs into the url parameter, causing the server to perform arbitrary requests; Veriti observed >10K attacks in a week targeting US government and financial organizations and highlighted misconfigured IPS/WAFs as a common failure point.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.