OpenAI Patches ChatGPT Prompt-Injection and Path-Traversal Flaw
ChatGPT’s file sandbox was designed to prevent users from downloading temporary uploaded content again, but a gap remained in the process used by the model to generate download links. Attackers could combine prompt injection with path traversal to obtain internal file-access paths. Although the flaw could not directly breach the sandbox to access highly sensitive data, it could still form part of a broader attack chain.
Security researcher zer0dac disclosed on July 6, 2026, that a valid URL could be obtained by first asking ChatGPT to edit an uploaded file and then requesting a download link on the pretext that the file had been accidentally deleted. A path-traversal string could then be added to the sandbox_path parameter in an attempt to read content outside the target path. OpenAI has redesigned the download URL generation process and patched the flaw.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.