Mark RadarMARK RADAR
EN

OpenAI Patches ChatGPT Prompt-Injection and Path-Traversal Flaw

1 reports · First detected 2026-07-06 · Last active 2026-07-06

ChatGPT’s file sandbox was designed to prevent users from downloading temporary uploaded content again, but a gap remained in the process used by the model to generate download links. Attackers could combine prompt injection with path traversal to obtain internal file-access paths. Although the flaw could not directly breach the sandbox to access highly sensitive data, it could still form part of a broader attack chain.

Security researcher zer0dac disclosed on July 6, 2026, that a valid URL could be obtained by first asking ChatGPT to edit an uploaded file and then requesting a download link on the pretext that the file had been accidentally deleted. A path-traversal string could then be added to the sandbox_path parameter in an attempt to read content outside the target path. OpenAI has redesigned the download URL generation process and patched the flaw.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR