OpenAI's ChatGPT has quickly become one of the hottest technologies in the world. However, API security vendor Salt Security has uncovered a set of critical vulnerabilities in the artificial intelligence (AI) model's extensions that could have allowed access to users’ third-party accounts and sensitive data.
Salt Security’s research team — Salt Labs — identified major security flaws within ChatGPT's plugin functionality, now known as GPTs. The plugins allow the AI chatbot to interact with external services, which enhances ChatGPT's applicability across various domains including software development, data management, educational and business environments.
“Plugins provide AI chatbots like ChatGPT access and permissions to perform tasks on behalf of users within third-party websites. For example, committing code to GitHub repositories or retrieving data from an organization's Google Drives,” the vendor noted.
These security flaws may introduce a new attack vector and enable threat actors to gain control of users’ accounts on third-party websites and access to personally identifiable information (PII) and other sensitive user data stored within third-party applications.
“Generative AI tools like ChatGPT have rapidly captivated the attention of millions across the world, boasting the potential to drastically improve efficiencies within both business operations as well as daily human life,” Yaniv Balmas, VP of research at Salt Security said in a statement. “As more organizations leverage this type of technology, attackers are too pivoting their efforts, finding ways to exploit these tools and subsequently gain access to sensitive data.”
“Our recent vulnerability discoveries within ChatGPT illustrate the importance of protecting the plugins within such technology to ensure that attackers cannot access critical business assets and execute account takeovers,” Balmas added.
3 different types of vulnerabilities within ChatGPT plugins The Salt Labs team uncovered three distinct types of vulnerabilities in their investigation within the ChatGPT plugins, which include the following:
- A flaw within ChatGPT itself when users install new plugins. The installation involves redirecting the user to the plugin website to receive a code to be approved by that individual. An attacker could trick the user into approving a malicious plugin instead of the intended one, which would enable the attacker to install their credentials on a victim’s account and access a host of proprietary information.
- A vulnerability was discovered within PluginLab (pluginlab.ai), a framework developers and companies use to develop plugins for ChatGPT. The team found that PluginLab did not properly authenticate user accounts, which would allow an attacker to insert another user ID and get a code that represents the victim. This may lead to an account takeover on the plugin.
- A vulnerability was uncovered within several plugins, which led to Open Authorization (OAuth) redirection manipulation. Attackers could insert a malicious URL and steal user credentials, leading to a full account takeover of the plugins.
Comments