3 ms·
Technical details: "The plugin does not authenticate the request, which means that the attacker can insert another memberId (aka the victim) and get a code that
by aviCC 3y ago
Technical details:
"The plugin does not authenticate the request, which means that the attacker can insert another memberId (aka the victim) and get a code that represents the victim. With that code, he can use ChatGPT and access the GitHub of the victim."
- aviCC 3y agoAnd a link, if you want to read the official blog post: https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data https://salt.security/blog/security-flaws-within-chatgpt-ext...