OpenAI Artifactory flaw let one ChatGPT session secretly send commands through another user’s connected account

Researchers say a flaw in OpenAI’s internal JFrog Artifactory setup could let one ChatGPT session covertly pass instructions to another user’s session and steal data such as email from connected Gmail accounts. Check Point said isolated code-execution containers could both read and write shared Artifactory item properties, creating a hidden cross-account channel via Base64-encoded data. The issue was disclosed in late June and had already been closed after the Artifactory instance was decommissioned.
Why it matters: This matters because users could have had data pulled from connected services without any visible sign inside the ChatGPT conversation. Organizations using AI tools with connected accounts should review what data sources are linked, tighten least-privilege access, and scrutinize isolation controls for agent and plugin workflows.

Sources

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
2026.09.08 100% relevant
The article establishes a distinct incident: a covert cross-account data channel in OpenAI’s Artifactory environment, related in timing and infrastructure to the Hugging Face attack but explicitly described as a separate issue rather than the same breach.
← Back to all stories