OpenAI Vulnerability: 48 Days, No Response

2 requilence 4 7/15/2025, 11:29:54 PM requilence.any.org ↗

Comments (4)

requilence · 25m ago
Reported a flaw to OpenAI that lets users peek at others' chat responses. Got an auto-reply on May 29th, radio silence since. Issue remains unpatched :( Avoided their bug bounty due to permanent NDAs preventing disclosure even after fixes. Following standard 45-day disclosure window—users should avoid sharing sensitive data until this is resolved.
poniko · 3m ago
The NDA part feels really murky.
fcpguru · 18m ago
well done, sounds very reasonable and following the rules.
requilence · 5m ago
Appreciate it. Just trying to do the right thing by both OpenAI and users here.