> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> ChatGPT Plugin Exploit Explained: From Prompt Injection to Accessing Private Data

[SOURCE] Embrace The Red [DATE: 28/05/2023 19:00] [LANGUAGE: EN]
If you are building ChatGPT plugins, LLM agents, tools or integrations this is a must read. This post explains how the first exploitable Cross Plugin Request Forgery was found in the wild and the fix which was applied. Indirect Prompt Injections Are Now A Reality With plugins and browsing support Indirect Prompt Injections are now a reality in the ChatGPT ecosystem. The real-world examples and demos provided by others and myself to raise awarness about this increasing problem have been mostly amusing and harmless, like making Bing Chat speak like a pirate, make ChatGPT add jokes at the end or having it do a Rickroll when reading YouTube transcripts.
[messages.read_original_source] →