ChatGPT Crawler Vulnerability: Potential for DDoS Attacks and Prompt Injection

4 Sources

A security researcher has uncovered a vulnerability in ChatGPT's crawler that could potentially be exploited for DDoS attacks and prompt injection, raising concerns about AI security and OpenAI's response to the issue.

News article

ChatGPT Crawler Vulnerability Discovered

Security researcher Benjamin Flesch has uncovered a significant vulnerability in OpenAI's ChatGPT crawler that could potentially be exploited to launch Distributed Denial of Service (DDoS) attacks on websites 1. The flaw, which Flesch describes as a "severe quality defect," lies in the handling of HTTP POST requests to a specific API endpoint used by ChatGPT 2.

How the Vulnerability Works

The vulnerability stems from ChatGPT's API not verifying if hyperlinks are repeated within a list or enforcing a limit on the total number of hyperlinks submitted 2. This allows an attacker to send thousands of hyperlinks in a single HTTP request, potentially overwhelming a target website. The ChatGPT crawler, using Cloudflare, accesses the site from different IP addresses with each request, making it difficult for victims to trace the source of the attack 2.

Potential for DDoS Attacks

Flesch demonstrated that a single API request could be amplified into 20 to 5,000 or more requests to a chosen victim's website every second 4. This amplification effect means an attacker can send a small number of requests to the ChatGPT API, resulting in a large number of requests to the victim's site 2.

Prompt Injection Vulnerability

In addition to the DDoS potential, Flesch identified another issue related to prompt injection. This flaw allows the crawler to process arbitrary questions using the same attributions API endpoint, rather than only fetching website data as intended 24.

Severity and Reporting

Flesch assigned the vulnerability a high severity rating of 8.6 CVSS, citing its network-based nature, low complexity in execution, and potential for high impact on availability 3. He reported the issue through multiple channels, including OpenAI's BugCrowd platform and Microsoft's security teams, but claims to have received no response 23.

OpenAI's Lack of Response

Despite multiple attempts to flag the vulnerability, Flesch states that the issue remains unresolved, and OpenAI has not acknowledged its existence 3. The Register reached out to OpenAI for comments but did not receive a reply 4.

Implications for AI Security

This vulnerability raises questions about the security practices in AI development. Flesch criticized OpenAI for failing to implement basic security measures, such as deduplicating URLs or limiting the size of URL lists 2. He speculated that the API might be an experimental project for OpenAI's AI agents, lacking necessary validation logic to prevent abuse 4.

Industry Reactions

Elad Schulman, founder and CEO of Lasso Security Inc., agreed with Flesch's conclusions and highlighted another potential exploit. He suggested that if a hacker compromised someone's OpenAI account, they could "easily spend a monthly budget of a large language model-based chatbot in just a day," potentially causing financial damage 1.

As AI continues to evolve, this incident underscores the need for companies to implement robust security measures to prevent the abuse of their services. It also highlights the importance of responsible disclosure and timely responses to reported vulnerabilities in the AI industry.

Explore today's top stories

Google Offers Free Weekend Access to Gemini's Veo 3 AI Video Generation Tool

Google is providing free users of its Gemini app temporary access to the Veo 3 AI video generation tool, typically reserved for paying subscribers, for a limited time this weekend.

Android Police logo9to5Google logoTechRadar logo

3 Sources

Technology

23 hrs ago

Google Offers Free Weekend Access to Gemini's Veo 3 AI

UK Government Considers Nationwide ChatGPT Plus Access in Talks with OpenAI

The UK's technology secretary and OpenAI's CEO discussed a potential multibillion-pound deal to provide ChatGPT Plus access to all UK residents, highlighting the government's growing interest in AI technology.

The Guardian logoDigital Trends logo

2 Sources

Technology

7 hrs ago

UK Government Considers Nationwide ChatGPT Plus Access in

AI-Generated Articles Slip Through Editorial Filters at Major Publications

Multiple news outlets, including Wired and Business Insider, have been duped by AI-generated articles submitted under a fake freelancer's name, raising concerns about the future of journalism in the age of artificial intelligence.

Wired logoThe Guardian logoFuturism logo

4 Sources

Technology

2 days ago

AI-Generated Articles Slip Through Editorial Filters at

Google's New Gemini-Powered Smart Speaker: A Glimpse into the Future of AI Home Assistants

Google inadvertently revealed a new smart speaker during its Pixel event, sparking speculation about its features and capabilities. The device is expected to be powered by Gemini AI and could mark a significant upgrade in Google's smart home offerings.

engadget logoGizmodo logoPCWorld logo

5 Sources

Technology

1 day ago

Google's New Gemini-Powered Smart Speaker: A Glimpse into

The Evolution of Search: How AI and Changing User Behavior Are Reshaping Digital Marketing

As AI and new platforms transform search behavior, brands must adapt their strategies beyond traditional SEO to remain visible in an increasingly fragmented digital landscape.

Gulf Business logoCampaign India logo

2 Sources

Technology

1 day ago

The Evolution of Search: How AI and Changing User Behavior
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo