Researcher uncovers a critical SSRF vulnerability in ChatGPT’s Custom GPT

Source Cryptopolitan

OpenAI’s large language model ChatGPT fixed a security flaw found earlier this week by a researcher within the “Actions” feature of Custom GPTs. Attackers could have exploited a Server-Side Request Forgery (SSRF) bug to expose internal credentials within the AI model’s cloud, the investigator claimed.

As an Open Security Engineer and bug hunter, SirLeeroyJenkins was creating his first Custom GPT, and he “sensed” there was an SSRF vulnerability. The Actions feature enables users to define external APIs using OpenAPI schemas for the AI to call them for specific tasks, such as fetching weather data.

While testing his own API, SirLeeroyJenkins discovered the system returned data from a user-provided URL. Alarmed by this behavior, he conducted more tests, suspecting a potential SSRF issue.

“Once I realized this feature could return data from any user-provided URL, the hacker instinct kicked in,” he said. “I had to check for SSRF.”

SSRF vulnerability could make custom GPTs unsafe 

As explained by Jenkins in his Medium post published earlier this week, Server-Side Request Forgery is a web vulnerability that tricks applications into making requests to unintended destinations. If the application does not properly validate user-supplied URLs, attackers can use the server’s access privileges to reach internal networks or cloud metadata services.

ChatGPT hacked using custom GPTs exploiting SSRF vulnerability
Basic full-read SSRF chart. Source: SirLeeroyJenkins Medium blog.

SSRF was prevalent enough to make the OWASP Top 10 list in 2021 and has now expanded its potential damage because insecure default configurations in cloud environments can expose critical systems.

Jenkins explained that there are two main SSRF types, namely full-read and blind. Full-read SSRF returns data from the target service directly to the attacker. At the same time, blind SSRF does not reveal the response but still allows them to interact with internal services, for example, through timing-based port scanning.

He tested the vulnerability by pointing the API URL to Azure’s Instance Metadata Service (IMDS), which stores sensitive cloud credentials. Access to this service normally requires the Metadata: True header, so he was alarmed when his initial attempts could not provide the header as requested.

The Custom GPT feature initially blocked the exploit because it enforced HTTPS URLs, while Azure IMDS operates over HTTP. Using a 302 redirect from an external HTTPS endpoint to the internal metadata URL, the server followed the redirect. However, Azure blocked access without the required header.

“Since the server followed 302 redirects, it returned the response from their internal metadata URL. Mission accomplished, right? Wrong. The response from their metadata service indicated that a required header was not being set,” SirLeeroyJenkins denoted.

After continuing to probe the responses, the feature allowed custom API keys that could be named arbitrarily. He attempted to name a key Metadata with the value true, where the required header was injected to grant the GPT access to the metadata service.

Jenkins promptly reported the vulnerability to OpenAI’s Bugcrowd program, and the issue was assigned high severity and then patched.

He also mentioned that Open Security previously used this type of SSRF attack chain to exploit a vulnerable invoice generation feature at a major global financial firm for security auditing.

OpenAI releases GPT-5.1 after the version 5.0 turmoil

In other related ChatGPT news, OpenAI announced the launch of GPT-5.1, boasting of several updates made from version 5.0 to improve instruction following and adaptive reasoning. 

“GPT-5.1 is out! It’s a nice upgrade. I particularly like the improvements in instruction following, and the adaptive thinking. The intelligence and style improvements are good too,” wrote CEO Sam Altman on X late Wednesday.

Tech writer Mehul Gupta tested GPT-5.1 against its predecessor, noting that GPT-5, while polished and helpful, sometimes overcomplicates simple tasks. GPT-5.1’s instant version supposedly had an improved understanding and subtle adaptive pauses that gave more “context-aware” responses.

In one test, Gupta asked both models to reply in six words. GPT-5 attempted to overexplain, while GPT-5.1 delivered a concise and correct answer. 

Altman also announced 7 new presets, including Default, Friendly, Efficient, Professional, Candid, or Quirky, have been added, but users can choose to “tune it themselves.”

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Solana Price Outlook: What To Expect From SOL In April 2026Solana (SOL) price enters April 2026 under pressure. March is closing at roughly -0.88%, extending a red streak that now stretches six consecutive months since October 2025.A head-and-shoulders breakd
Author  Beincrypto
Mar 31, Tue
Solana (SOL) price enters April 2026 under pressure. March is closing at roughly -0.88%, extending a red streak that now stretches six consecutive months since October 2025.A head-and-shoulders breakd
placeholder
3 Meme Coins To Watch In April 2026April 2026 brings a fresh set of meme coins to watch as technical setups, derivatives shifts, and concentrated wallet structures create potential turning points across multiple tokens.BeInCrypto analy
Author  Beincrypto
Mar 31, Tue
April 2026 brings a fresh set of meme coins to watch as technical setups, derivatives shifts, and concentrated wallet structures create potential turning points across multiple tokens.BeInCrypto analy
placeholder
SpaceX plans a $70-75 billion IPO at a $1.75 trillion valuationSpaceX is pushing for what could be the biggest stock offering ever. But there’s a problem with the timing. Reports last week said the company plans to file IPO paperwork as soon as this week. They want to raise $70-$75 billion, with the company valued at $1.75 trillion. Those are massive numbers that would shatter […]
Author  Cryptopolitan
Mar 31, Tue
SpaceX is pushing for what could be the biggest stock offering ever. But there’s a problem with the timing. Reports last week said the company plans to file IPO paperwork as soon as this week. They want to raise $70-$75 billion, with the company valued at $1.75 trillion. Those are massive numbers that would shatter […]
placeholder
If the US Troops Enter Iran, What Happens to Bitcoin? Lessons From Past WarsMarkets are already reacting to rising geopolitical risk. Several Polymarket insiders who successfully bet on the start date of the Iran war are now betting heavily on US boots on the ground in Iran.N
Author  Beincrypto
7 hours ago
Markets are already reacting to rising geopolitical risk. Several Polymarket insiders who successfully bet on the start date of the Iran war are now betting heavily on US boots on the ground in Iran.N
placeholder
Silver Price Recovers From 2026 Low, but April Arrives With a 36% Downside ThreatSilver (XAG/USD) price has bounced roughly 18% from its 2026 low, currently trading above $72. The recovery followed a hidden bullish divergence that began forming in December. Additionally, the lates
Author  Beincrypto
7 hours ago
Silver (XAG/USD) price has bounced roughly 18% from its 2026 low, currently trading above $72. The recovery followed a hidden bullish divergence that began forming in December. Additionally, the lates
goTop
quote