A researcher disclosed a proof-of-concept vulnerability chain in ChatGPT that allegedly allowed access to files inside its sandboxed environment by combining a prompt-based guardrail bypass with a path traversal flaw in the file download workflow. The issue reportedly began when an uploaded file was made downloadable after the model was prompted to bypass its normal refusal to generate a download link for temporary files, producing a valid backend URL tied to the upload.
The researcher said the download endpoint accepted a manipulable sandbox_path parameter that could be altered with traversal sequences to retrieve restricted files such as /etc/passwd, effectively creating a local file inclusion primitive within the sandbox. OpenAI reportedly mitigated the issue by redesigning the URL download flow, and the write-ups noted that the sandboxed execution environment limited direct exposure of highly sensitive host data, though the flaw still illustrated how LLM guardrail manipulation can be chained with traditional web vulnerabilities.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
OpenAI remediated the reported issue by changing or redesigning the URL download flow, according to the researcher and subsequent reporting.
A researcher identified and documented a proof-of-concept chain in ChatGPT that allegedly combined a prompt-based guardrail bypass with a path traversal/local file inclusion issue in the file download workflow, enabling retrieval of files such as /etc/passwd from the sandboxed environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceinfosecwriteups.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.