Mark RadarMARK RADAR
About
EN
Sign in

OpenAI Patches ChatGPT Prompt-Injection and Path-Traversal Flaw

1 reports · First detected 2026-07-06 · Last active 2026-07-06

ChatGPT’s file sandbox was designed to prevent users from downloading temporary uploaded content again, but a gap remained in the process used by the model to generate download links. Attackers could combine prompt injection with path traversal to obtain internal file-access paths. Although the flaw could not directly breach the sandbox to access highly sensitive data, it could still form part of a broader attack chain.

Security researcher zer0dac disclosed on July 6, 2026, that a valid URL could be obtained by first asking ChatGPT to edit an uploaded file and then requesting a download link on the pretext that the file had been accidentally deleted. A path-traversal string could then be added to the sandbox_path parameter in an attempt to read content outside the target path. OpenAI has redesigned the download URL generation process and patched the flaw.

All Coverage

1 original reports

The Backstory

The history behind this event
OpenAI Patches AgentForger Flaw in ChatGPT Workspace Agents2026-07-27 · 1 reports · similarity 0.82

OpenAI’s ChatGPT Workspace Agents can connect to corporate services including Outlook, Slack and Google Drive and run scheduled tasks for employees. Zenity Labs said AgentForger, a cross-site request forgery vulnerability, abused those capabilities to place an attacker-controlled agent inside an organization’s trust boundary. The flaw was significant because the rogue agent could inherit a user’s existing identity and connector permissions, creating persistent access to sensitive data without requiring attackers to compromise each external service separately.

Zenity reported the flaw through Bugcrowd on June 4, 2026; OpenAI accepted it on June 5 and deployed a fix on June 8, according to research published July 23. A logged-in user only had to click a crafted URL for the agent to be built, authorized and executed without another confirmation. Zenity demonstrated a scheduled command loop running every five minutes that could search email and files, harvest credentials, impersonate employees and prepare a $242,500 wire-fraud lure.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)