ChatGPT Plugin Flaw – attackers could access private GitHub repos of others
1–4 of 4 posts
Re: ChatGPT Plugin Flaw – attackers could access private GitHub repos of others
#2[deleted]
Re: ChatGPT Plugin Flaw – attackers could access private GitHub repos of others
#3Technical details:
"The plugin does not authenticate the request, which means that the attacker can insert another memberId (aka the victim) and get a code that represents the victim. With that code, he can use ChatGPT and access the GitHub of the victim."
Re: ChatGPT Plugin Flaw – attackers could access private GitHub repos of others
#4Technical details: "The plugin does not authenticate the request, which means that the attacker can insert another memberId (aka the victim) and get a code that represents the victim. With that code, he can use ChatGPT and access the GitHub of the victim."
And a link, if you want to read the official blog post:
https://salt.security/blog/security-flaws-within-chatgpt-ext...