Search

Find a vulnerability

Search criteria

    5 vulnerabilities found for ChatGPT

    CVE-2024-27564 (GCVE-0-2024-27564)

    Vulnerability from nvd – Published: 2024-03-05 00:00 – Updated: 2025-03-20 14:28
    VLAI Previdian
    Summary
    pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-05 20:31 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    dirk1983 mm1.ltd source code Affected: f9f4bbc99eed7210b291ec116bd57b3d8276bee5 (git)
    Create a notification for this product.
    dirk1983 chatgpt Affected: f9f4bbc
        cpe:2.3:a:dirk1983:chatgpt:f9f4bbc:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:34:52.359Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/dirk1983/chatgpt/issues/114"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:dirk1983:chatgpt:f9f4bbc:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "chatgpt",
                "vendor": "dirk1983",
                "versions": [
                  {
                    "status": "affected",
                    "version": "f9f4bbc"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-27564",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-05T20:31:20.672582Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-20T14:28:44.751Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "mm1.ltd source code",
              "vendor": "dirk1983",
              "versions": [
                {
                  "status": "affected",
                  "version": "f9f4bbc99eed7210b291ec116bd57b3d8276bee5",
                  "versionType": "git"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-20T03:45:46.840Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/dirk1983/chatgpt/issues/114"
            },
            {
              "url": "https://web.archive.org/save/https://github.com/dirk1983/chatgpt/issues/114"
            },
            {
              "url": "https://web.archive.org/web/20250320032559/https://github.com/dirk1983/chatgpt/blob/f9f4bbc99eed7210b291ec116bd57b3d8276bee5/pictureproxy.php"
            },
            {
              "url": "https://web.archive.org/web/20250320031248/https://mm1.ltd/"
            },
            {
              "url": "https://web.archive.org/save/https://github.com/dirk1983/chatgpt/blob/f9f4bbc99eed7210b291ec116bd57b3d8276bee5/README.md"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-27564",
        "datePublished": "2024-03-05T00:00:00.000Z",
        "dateReserved": "2024-02-26T00:00:00.000Z",
        "dateUpdated": "2025-03-20T14:28:44.751Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-27564 (GCVE-0-2024-27564)

    Vulnerability from cvelistv5 – Published: 2024-03-05 00:00 – Updated: 2025-03-20 14:28
    VLAI Previdian
    Summary
    pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-05 20:31 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    dirk1983 mm1.ltd source code Affected: f9f4bbc99eed7210b291ec116bd57b3d8276bee5 (git)
    Create a notification for this product.
    dirk1983 chatgpt Affected: f9f4bbc
        cpe:2.3:a:dirk1983:chatgpt:f9f4bbc:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:34:52.359Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/dirk1983/chatgpt/issues/114"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:dirk1983:chatgpt:f9f4bbc:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "chatgpt",
                "vendor": "dirk1983",
                "versions": [
                  {
                    "status": "affected",
                    "version": "f9f4bbc"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-27564",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-05T20:31:20.672582Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-03-20T14:28:44.751Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "mm1.ltd source code",
              "vendor": "dirk1983",
              "versions": [
                {
                  "status": "affected",
                  "version": "f9f4bbc99eed7210b291ec116bd57b3d8276bee5",
                  "versionType": "git"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-03-20T03:45:46.840Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/dirk1983/chatgpt/issues/114"
            },
            {
              "url": "https://web.archive.org/save/https://github.com/dirk1983/chatgpt/issues/114"
            },
            {
              "url": "https://web.archive.org/web/20250320032559/https://github.com/dirk1983/chatgpt/blob/f9f4bbc99eed7210b291ec116bd57b3d8276bee5/pictureproxy.php"
            },
            {
              "url": "https://web.archive.org/web/20250320031248/https://mm1.ltd/"
            },
            {
              "url": "https://web.archive.org/save/https://github.com/dirk1983/chatgpt/blob/f9f4bbc99eed7210b291ec116bd57b3d8276bee5/README.md"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-27564",
        "datePublished": "2024-03-05T00:00:00.000Z",
        "dateReserved": "2024-02-26T00:00:00.000Z",
        "dateUpdated": "2025-03-20T14:28:44.751Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    AVID-2023-V027

    Vulnerability from avid – Published: 2023-03-31 – Updated: 2023-03-31 LLM Evaluation
    Summary
    When asked to recommend papers on explainability, privacy, adversarial ML, etc. ChatGPT recommends papers that (a) may not always exist, (b) mixes up correct and incorrect information, e.g. correct title but wrong authors, or (c) have incomplete information on authors.
    Risk domain
    Ethics
    SEP view
    E0402: Generative Misinformation
    Lifecycle
    L05: Evaluation, L06: Deployment
    Organisations
    OpenAI (deployer), OpenAI (developer)
    Affected artifacts
    Artifact Type
    ChatGPT System
    References
    URL Label
    ../img/R00031.png Screenshot of example answer

    {
      "affects": {
        "artifacts": [
          {
            "name": "ChatGPT",
            "type": "System"
          }
        ],
        "deployer": [
          "OpenAI"
        ],
        "developer": [
          "OpenAI"
        ]
      },
      "credit": [
        {
          "lang": "eng",
          "value": "Jaydeep Borkar, N/A"
        }
      ],
      "data_type": "AVID",
      "data_version": "0.2",
      "description": {
        "lang": "eng",
        "value": "When asked to recommend papers on explainability, privacy, adversarial ML, etc. ChatGPT recommends papers that (a) may not always exist, (b) mixes up correct and incorrect information, e.g. correct title but wrong authors, or (c) have incomplete information on authors."
      },
      "impact": {
        "avid": {
          "lifecycle_view": [
            "L05: Evaluation",
            "L06: Deployment"
          ],
          "risk_domain": [
            "Ethics"
          ],
          "sep_view": [
            "E0402: Generative Misinformation"
          ],
          "taxonomy_version": "0.2"
        }
      },
      "last_modified_date": "2023-03-31",
      "metadata": {
        "vuln_id": "AVID-2023-V027"
      },
      "problemtype": {
        "classof": "LLM Evaluation",
        "description": {
          "lang": "eng",
          "value": "ChatGPT generates false or incomplete references to scientific literature"
        },
        "type": "Issue"
      },
      "published_date": "2023-03-31",
      "references": [
        {
          "label": "Screenshot of example answer",
          "type": "screenshot",
          "url": "../img/R00031.png"
        }
      ],
      "reports": [
        {
          "name": "ChatGPT links wrong authors to papers",
          "report_id": "AVID-2023-R0003",
          "type": "Issue"
        }
      ]
    }

    AVID-2023-V026

    Vulnerability from avid – Published: 2023-03-31 – Updated: 2023-03-31 LLM Evaluation
    Summary
    When prompting ChatGPT with lexical constraints, e.g. "Generate a text without the letter "e" in it", ChatGPT almost always fails to follow these constraints.
    Risk domain
    Performance
    SEP view
    P0204: Accuracy
    Lifecycle
    L02: Data Understanding, L04: Model Development, L05: Evaluation, L06: Deployment
    Organisations
    OpenAI (deployer), OpenAI (developer)
    Affected artifacts
    Artifact Type
    ChatGPT System
    References
    URL Label
    https://www.gwern.net/GPT-3#bpes Gwern's analysis of lexical constraints and ChatGPT
    https://paperswithcode.com/paper/most-language-mo… Most Language Models can be Poets too: An AI Writing Assistant and Constrained Text Generation Studio

    {
      "affects": {
        "artifacts": [
          {
            "name": "ChatGPT",
            "type": "System"
          }
        ],
        "deployer": [
          "OpenAI"
        ],
        "developer": [
          "OpenAI"
        ]
      },
      "credit": [
        {
          "lang": "eng",
          "value": "Allen Roush, Oracle Corporation"
        }
      ],
      "data_type": "AVID",
      "data_version": "0.2",
      "description": {
        "lang": "eng",
        "value": "When prompting ChatGPT with lexical constraints, e.g. \"Generate a text without the letter \"e\" in it\", ChatGPT almost always fails to follow these constraints. "
      },
      "impact": {
        "avid": {
          "lifecycle_view": [
            "L02: Data Understanding",
            "L04: Model Development",
            "L05: Evaluation",
            "L06: Deployment"
          ],
          "risk_domain": [
            "Performance"
          ],
          "sep_view": [
            "P0204: Accuracy"
          ],
          "taxonomy_version": "0.2"
        }
      },
      "last_modified_date": "2023-03-31",
      "metadata": {
        "vuln_id": "AVID-2023-V026"
      },
      "problemtype": {
        "classof": "LLM Evaluation",
        "description": {
          "lang": "eng",
          "value": "ChatGPT fails to follow lexical constraints"
        },
        "type": "Advisory"
      },
      "published_date": "2023-03-31",
      "references": [
        {
          "label": "Gwern\u0027s analysis of lexical constraints and ChatGPT",
          "type": "source",
          "url": "https://www.gwern.net/GPT-3#bpes"
        },
        {
          "label": "Most Language Models can be Poets too: An AI Writing Assistant and Constrained Text Generation Studio",
          "type": "source",
          "url": "https://paperswithcode.com/paper/most-language-models-can-be-poets-too-an-ai"
        }
      ],
      "reports": [
        {
          "name": "ChatGPT fails to follow lexical constraints",
          "report_id": "AVID-2023-R0002",
          "type": "Advisory"
        }
      ]
    }

    AVID-2023-V028

    Vulnerability from avid – Published: 2023-03-31 – Updated: 2023-03-31 LLM Evaluation
    Summary
    Frameworks like langchain (Python) and boxcars.ai (Ruby) offer apps and scripts to directly execute queries through LLMs as a built-in feature. In the context of boxcars.ai, this makes it really easy to perform remote code execution or SQL injection. All you have to do is ask politely! See the references for more details.
    Risk domain
    Ethics
    SEP view
    S0100: Software Vulnerability, S0201: Model Compromise, S0301: Information Leak, S0202: Software Compromise, S0601: Ingest Poisoning
    Lifecycle
    L04: Model Development, L05: Evaluation, L06: Deployment
    Organisations
    OpenAI (deployer), boxcars.ai (deployer), OpenAI (developer)
    Affected artifacts
    Artifact Type
    ChatGPT System
    boxcars.ai System
    References
    URL Label
    https://blog.luitjes.it/posts/injectgpt-most-poli… InjectGPT: the most polite exploit ever
    https://www.reddit.com/r/netsec/comments/121gpay/… Reddit thread on InjectGPT

    {
      "affects": {
        "artifacts": [
          {
            "name": "ChatGPT",
            "type": "System"
          },
          {
            "name": "boxcars.ai",
            "type": "System"
          }
        ],
        "deployer": [
          "OpenAI",
          "boxcars.ai"
        ],
        "developer": [
          "OpenAI"
        ]
      },
      "credit": [
        {
          "lang": "eng",
          "value": "Lucas Luitjes, N/A"
        }
      ],
      "data_type": "AVID",
      "data_version": "0.2",
      "description": {
        "lang": "eng",
        "value": "Frameworks like langchain (Python) and boxcars.ai (Ruby) offer apps and scripts to directly execute queries through LLMs as a built-in feature. In the context of boxcars.ai, this makes it really easy to perform remote code execution or SQL injection. All you have to do is ask politely! \nSee the references for more details."
      },
      "impact": {
        "avid": {
          "lifecycle_view": [
            "L04: Model Development",
            "L05: Evaluation",
            "L06: Deployment"
          ],
          "risk_domain": [
            "Ethics"
          ],
          "sep_view": [
            "S0100: Software Vulnerability",
            "S0201: Model Compromise",
            "S0301: Information Leak",
            "S0202: Software Compromise",
            "S0601: Ingest Poisoning"
          ],
          "taxonomy_version": "0.2"
        }
      },
      "last_modified_date": "2023-03-31",
      "metadata": {
        "vuln_id": "AVID-2023-V028"
      },
      "problemtype": {
        "classof": "LLM Evaluation",
        "description": {
          "lang": "eng",
          "value": "It is possible to make ChatGPT perform remote code execution just by asking politely"
        },
        "type": "Advisory"
      },
      "published_date": "2023-03-31",
      "references": [
        {
          "label": "InjectGPT: the most polite exploit ever",
          "type": "source",
          "url": "https://blog.luitjes.it/posts/injectgpt-most-polite-exploit-ever/"
        },
        {
          "label": "Reddit thread on InjectGPT",
          "type": "source",
          "url": "https://www.reddit.com/r/netsec/comments/121gpay/injectgpt_remote_code_execution_by_asking_nicely/"
        }
      ],
      "reports": [
        {
          "name": "It is possible to make ChatGPT perform remote code execution just by asking politely",
          "report_id": "AVID-2023-R0004",
          "type": "Advisory"
        }
      ]
    }