Critical ChatGPT Plug-in Vulnerabilities Expose Sensitive Data
ID: 64742cce-d0b7-5141-ab83-0787b3ad0e82
STIX ID: report--64742cce-d0b7-5141-ab83-0787b3ad0e82
Feed Name: Dark Reading
Salt Labs researchers disclosed three critical vulnerabilities affecting ChatGPT plug-ins and the PluginLab framework that could allow attackers to perform unauthorized account takeovers — including malicious plug-in installation via approval redirection, authentication bypass in the PluginLab framework, and OAuth redirection manipulation to steal credentials. The issues have been patched and there is no evidence of exploitation; organizations are advised to update software, audit installed plug-ins/GPTs, and review third-party account exposures and permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
