{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0431",
  "aliases": [],
  "published": "2026-09-08T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "ChatGPT with code containers and a connected Gmail account, during ordinary use, processed a hidden cross-account task and returned the victim's Gmail data to an attacker.",
  "details": "## What\n\nCheck Point Research demonstrated a covert channel between ChatGPT sessions belonging to different accounts. A hidden instruction made the victim's session perform a second task using its connected apps while returning a normal visible answer; the proof of concept retrieved data from the victim's Gmail account and relayed it to the attacker.\n\n## Detection\n\nCheck Point Research reproduced the behavior in a proof of concept.\n\n## Fix\n\nReview connected-app permissions and treat hidden instructions in shared conversations or custom GPTs as untrusted.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "chatgpt"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "data-exfiltration",
        "prompt-injection-to-tool",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-1427"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI01",
          "ASI02"
        ],
        "atlas": [
          "AML.T0051.001",
          "AML.T0085.001"
        ]
      },
      "cveBoundary": "exposed-surface",
      "noCveReason": "No CVE was assigned in the public disclosure.",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Limit connected-app access and inspect hidden instructions in shared ChatGPT contexts.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "agent.connected-apps",
            "to": "least privilege",
            "why": "The demonstrated task used permissions already available to the victim session.",
            "owner": "operator"
          },
          {
            "type": "reconfigure",
            "target": "openai.chatgpt.codeContainers",
            "to": "isolated between accounts",
            "why": "Recommended: the leak ran through a channel between sessions of different accounts.",
            "owner": "harness-vendor"
          },
          {
            "type": "reconfigure",
            "target": "openai.chatgpt.connectedApps",
            "to": "actions shown in the visible conversation",
            "why": "Recommended: the Gmail action completed with no approval opportunity in the visible conversation.",
            "owner": "harness-vendor"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "ChatGPT code containers with connected apps",
          "any": false,
          "status": "confirmed",
          "source": "https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any ordinary ChatGPT task in a session with connected apps",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Code-execution containers and the connected Gmail app",
          "status": "confirmed",
          "source": "https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/"
        },
        "approval": {
          "value": "The hidden Gmail action completed without an approval opportunity in the visible conversation",
          "mode": "no-prompt-by-design",
          "status": "confirmed",
          "source": "https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/"
        },
        "inputControl": "content-author",
        "agentAction": "ChatGPT performs a hidden task with the victim session's tools and connected data.",
        "harm": "data-exfiltration",
        "divergence": "goal-hijacked",
        "reach": {
          "value": "The victim's connected Gmail data",
          "kinds": [
            "inbox"
          ],
          "status": "confirmed",
          "source": "https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/"
        }
      },
      "occurrence": {
        "basis": "demonstrated",
        "reportedBy": "researcher"
      },
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      },
      "severityBasis": "harm-reach"
    }
  }
}
