Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets

Posted on November 12, 2025November 12, 2025 By CWS

A Server-Facet Request Forgery (SSRF) vulnerability in OpenAI’s ChatGPT. The flaw, lurking within the Customized GPT “Actions” characteristic, allowed attackers to trick the system into accessing inner cloud metadata, doubtlessly exposing delicate Azure credentials.

The bug, found by Open Safety throughout informal experimentation, highlights the dangers of user-controlled URL dealing with in AI instruments.

SSRF vulnerabilities happen when purposes blindly fetch sources from user-supplied URLs, enabling attackers to coerce servers into querying unintended locations. This will bypass firewalls, probe inner networks, or extract information from privileged providers.

As cloud adoption grows, SSRF’s risks amplify; main suppliers like AWS, Azure, and Google Cloud expose metadata endpoints, equivalent to Azure’s at which include occasion particulars and API tokens.

The Open Net Software Safety Mission (OWASP) added SSRF to its Prime 10 listing in 2021, underscoring its prevalence in trendy apps.

The researcher, experimenting with Customized GPTs, a premium ChatGPT Plus device for constructing tailor-made AI assistants, seen the “Actions” part. This lets customers outline exterior APIs through OpenAPI schemas, permitting the GPT to name them for duties like climate lookups.

The interface features a “Check” button to confirm requests and helps authentication headers. Recognizing the potential for SSRF, the researcher examined by pointing the API URL to Azure’s Occasion Metadata Service (IMDS).

Preliminary makes an attempt failed as a result of the characteristic enforced HTTPS URLs, whereas IMDS makes use of HTTP. Undeterred, the researcher bypassed this utilizing a 302 redirect from an exterior HTTPS endpoint (through instruments like ssrf.cvssadvisor.com) to the inner metadata URL. The server adopted the redirect, however Azure blocked entry with out the “Metadata: true” header.

Additional probing revealed a workaround: the authentication settings allowed customized “API keys.” Naming one “Metadata” with worth “true” injected the required header.

Success! The GPT returned IMDS information, together with an OAuth2 token for Azure’s administration API (requested through /metadata/id/oauth2/token?useful resource=

This token granted direct entry to OpenAI’s cloud surroundings, enabling useful resource enumeration or escalation.

The affect was extreme. In cloud setups, such tokens may pivot to full compromise, as seen in previous Open Safety pentests the place SSRF led to distant code execution throughout tons of of cases.

For ChatGPT, it risked leaking manufacturing secrets and techniques, although the researcher famous it wasn’t essentially the most catastrophic they’d discovered.

Reported promptly to OpenAI’s Bugcrowd program, the vulnerability was assigned excessive severity and obtained a swift patch. OpenAI confirmed the repair, stopping additional exploitation.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:ChatGPT, Custom, Exploiting, Expose, GPTs, Hacked, Secrets, SSRF, Vulnerability

Post navigation

Previous Post: Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy
Next Post: Authentication Coercion Attack Tricks Windows Machines into Revealing Credentials to Attack-controlled Servers

Related Posts

Stellantis, the Maker of Citroën, FIAT, Jeep, and Other Cars, Confirms Data Breach Cyber Security News
How to Stay Ahead of Vulnerabilities Cyber Security News
Interlock Ransomware Employs ClickFix Technique to Run Malicious Commands on Windows Machines Cyber Security News
Multiple GitLab Vulnerabilities Allow Attackers to Achieve Complete Account Takeover Cyber Security News
New Tykit Phishing Kit Mimics Microsoft 365 Login Pages to Steal Corporate Account Credentials Cyber Security News
Hackers Deliver SSH-Tor Backdoor Via Weaponized Military Documents in ZIP Files Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
  • CYBERCOM 2.0: Pentagon Unveils Plan to Fix Cyber Talent Shortfalls
  • Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens
  • In Other News: Deepwatch Layoffs, macOS Vulnerability, Amazon AI Bug Bounty
  • Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
  • CYBERCOM 2.0: Pentagon Unveils Plan to Fix Cyber Talent Shortfalls
  • Malicious npm Package with 206k Downloads Attacking GitHub-Owned Repositories to Exfiltrate Tokens
  • In Other News: Deepwatch Layoffs, macOS Vulnerability, Amazon AI Bug Bounty
  • Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News