OpenAI Artifactory vulnerability exposed covert data-stealing channel

Researchers disclosed a vulnerability in OpenAI's Artifactory that allowed unauthorized accounts to send hidden tasks—such as retrieving email data from connected Gmail accounts—through ChatGPT's internal system as of September 8–9, 2026. The flaw was exploited alongside a concurrent Hugging Face zero-day attack.

3 reportstech · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack https://www. theregister.com/security/2026/ 09/08/openais-artifactory-opened-covert-data-stealing-channel-alongsi

mastodon:infosec-exchangeother20d ago kagi ↗

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack https://www. theregister.com/security/2026/ 09/08/openais-artifactory-opened-covert-data-stealing-channel-alongside-hugging-face-attack/5295124 Článek popisuje bezpečnostní problém, který odhalila firma Check Point Research u systému OpenAI. V systému ChatGPT existoval tajný kanál, který umožnil jednomu uživatel

A secret channel running through ChatGPT's internal JFrog Artifactory instance allowed one account to send hidden tasks - such as retrieving email data from a connected Gmail account - to a ChatGPT se

mastodon:infosec-exchangeother20d ago kagi ↗

A secret channel running through ChatGPT's internal JFrog Artifactory instance allowed one account to send hidden tasks - such as retrieving email data from a connected Gmail account - to a ChatGPT session under another account. https://www. theregister.com/security/2026/ 09/08/openais-artifactory-opened-covert-data-stealing-channel-alongside-hugging-face-attack/5295124