OpenAI Patches ChatGPT Prompt-Injection and Path-Traversal Flaw
ChatGPT’s file sandbox was designed to prevent users from downloading temporary uploaded content again, but a gap remained in the process used by the model to generate download links. Attackers could combine prompt injection with path traversal to obtain internal file-access paths. Although the flaw could not directly breach the sandbox to access highly sensitive data, it could still form part of a broader attack chain.
Security researcher zer0dac disclosed on July 6, 2026, that a valid URL could be obtained by first asking ChatGPT to edit an uploaded file and then requesting a download link on the pretext that the file had been accidentally deleted. A path-traversal string could then be added to the sandbox_path parameter in an attempt to read content outside the target path. OpenAI has redesigned the download URL generation process and patched the flaw.
All Coverage
1 original reportsThe Backstory
The history behind this eventOpenAI Patches AgentForger Flaw in ChatGPT Workspace Agents
OpenAI’s ChatGPT Workspace Agents can connect to corporate services including Outlook, Slack and Google Drive and run scheduled tasks for employees. Zenity Labs said AgentForger, a cross-site request forgery vulnerability, abused those capabilities to place an attacker-controlled agent inside an organization’s trust boundary. The flaw was significant because the rogue agent could inherit a user’s existing identity and connector permissions, creating persistent access to sensitive data without requiring attackers to compromise each external service separately.
Zenity reported the flaw through Bugcrowd on June 4, 2026; OpenAI accepted it on June 5 and deployed a fix on June 8, according to research published July 23. A logged-in user only had to click a crafted URL for the agent to be built, authorized and executed without another confirmation. Zenity demonstrated a scheduled command loop running every five minutes that could search email and files, harvest credentials, impersonate employees and prepare a $242,500 wire-fraud lure.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →