ACVEAgent configuration vulnerability registry

ACVE-2026-0431

ChatGPT with code containers and a connected Gmail account, during ordinary use, processed a hidden cross-account task and returned the victim's Gmail data to an attacker.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

Description

What

Check Point Research demonstrated a covert channel between ChatGPT sessions belonging to different accounts. A hidden instruction made the victim's session perform a second task using its connected apps while returning a normal visible answer; the proof of concept retrieved data from the victim's Gmail account and relayed it to the attacker.

Detection

Check Point Research reproduced the behavior in a proof of concept.

Fix

Review connected-app permissions and treat hidden instructions in shared conversations or custom GPTs as untrusted.

Fix

Limit connected-app access and inspect hidden instructions in shared ChatGPT contexts.

  • Reconfigure agent.connected-apps to least privilege. The demonstrated task used permissions already available to the victim session. Owner: operator
  • Reconfigure openai.chatgpt.codeContainers to isolated between accounts. Recommended: the leak ran through a channel between sessions of different accounts. Owner: harness-vendor
  • Reconfigure openai.chatgpt.connectedApps to actions shown in the visible conversation. Recommended: the Gmail action completed with no approval opportunity in the visible conversation. Owner: harness-vendor

References

REPORT

Report a problemJSON