Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

ChatGPT Vulnerability Exposed Underlying Cloud Infrastructure

Posted on November 13, 2025November 13, 2025 By CWS

A researcher has disclosed the small print of a lately patched ChatGPT vulnerability which will have uncovered a number of the AI chatbot’s underlying cloud infrastructure.

Jacob Krut, a bug bounty hunter and safety engineer at Open Safety, found the vulnerability whereas engaged on making a customized GPT —a customized model of ChatGPT tailor-made to a particular function or space of experience.

The researcher discovered the weak spot within the ‘Actions’ part, the place customers outline how the customized GPT can work together with exterior providers through APIs. The characteristic relied on user-provided URLs that weren’t correctly validated, permitting an attacker to conduct a server-side request forgery (SSRF) assault.

SSRF vulnerabilities may be exploited utilizing specifically crafted URLs to make unauthorized requests to inner community sources that the attacker would usually not have the ability to entry. 

Within the case of ChatGPT, Krut was in a position to exploit the vulnerability to question a neighborhood endpoint related to the Azure Occasion Metadata Service (IMDS), an Azure cloud platform element used for utility configuration and administration. 

The IMDS id authenticates the service to different sources. By acquiring the ChatGPT Azure IMDS id’s entry token, the researcher may have gained entry to the underlying Azure cloud infrastructure utilized by OpenAI.

The vulnerability was reported to OpenAI via its bug bounty program on the BugCrowd platform. The researcher mentioned the seller assigned it a ‘excessive severity’ score and shortly patched it.  

It’s unclear if a bug bounty has been paid out for the safety gap. In Could, OpenAI began providing as much as $100,000 for vital vulnerabilities, however the common payout previously three months has been lower than $800, and the very best publicly listed reward since Could was $5,000.Commercial. Scroll to proceed studying.

“This SSRF in ChatGPT’s Customized GPT Actions is a textbook instance of how small validation gaps on the framework layer can cascade into cloud-level publicity and highlights the severity of this often-overlooked assault vector,” mentioned Christopher Jess, senior R&D supervisor at utility safety agency Black Duck.

“SSRF has been within the OWASP High 10 since 2021 due to exactly this potential blast radius: a single server-side request can pivot into inner providers, metadata endpoints, and privileged cloud identities,” Jess added.

Associated: ChatGPT Focused in Server-Facet Information Theft Assault

Associated: Researchers Hack ChatGPT Reminiscences and Internet Search Options

Associated: AI Sidebar Spoofing Places ChatGPT Atlas, Perplexity Comet and Different Browsers at Threat

Associated: ChatGPT Tricked Into Fixing CAPTCHAs

Security Week News Tags:ChatGPT, Cloud, Exposed, Infrastructure, Underlying, Vulnerability

Post navigation

Previous Post: MastaStealer Weaponizes Windows LNK Files, Executes PowerShell Command, and Evades Defender
Next Post: Google Sues ‘Lighthouse’ Phishing-as-a-service Kit Behind Massive Phishing Attacks

Related Posts

Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks Security Week News
Rethinking Success in Security: Why Climbing the Corporate Ladder Isn’t Always the Goal Security Week News
Adobe Patches Nearly 140 Vulnerabilities Security Week News
Recently Disrupted DanaBot Leaked Valuable Data for 3 Years Security Week News
Australian Human Rights Commission Discloses Data Breach Security Week News
Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Infostealer Malware Delivered in EmEditor Supply Chain Attack
  • Fresh MongoDB Vulnerability Exploited in Attacks
  • 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
  • Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak
  • MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Infostealer Malware Delivered in EmEditor Supply Chain Attack
  • Fresh MongoDB Vulnerability Exploited in Attacks
  • 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
  • Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak
  • MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark