A Server-Side Request Forgery (SSRF) vulnerability in OpenAI 's ChatGPT , hidden in the Custom GPT's “ Actions ” function, allowed attackers to trick the system into accessing internal cloud metadata, potentially exposing sensitive Azure credentials.
See also: Researchers trick ChatGPT into inserting prompts into itself

The bug, discovered by Open Security during casual experimentation, highlights the dangers of user-controlled URL handling in AI tools.
SSRF vulnerabilities occur when applications blindly retrieve resources from user-provided URLs, allowing attackers to force servers to query unintended destinations. This can bypass firewalls, probe internal networks, or extract data from privileged services.
As cloud adoption increases, the risks of SSRF are intensifying. Large providers like AWS, Azure, and Google Cloud expose metadata endpoints, such as Azure's at http://169.254.169.254, which contain instance details and API tokens.
The Open Web Application Security Project (OWASP) added SSRF to its top 10 list in 2021, highlighting its prevalence in modern applications.
The researcher, experimenting with Custom GPTs, a premium ChatGPT Plus tool for creating custom AI assistants, noticed the “Actions” section. This allows users to define external APIs via OpenAPI schemas, allowing GPT to call them for tasks like weather searches.
See also: OpenAI: Are GPT-5.1, GPT-5.1 Reasoning & GPT-5.1 Pro coming?

The interface includes a “Test” button to verify requests and supports authentication headers. Identifying the possibility of SSRF, the researcher conducted tests by directing the API URL to Azure’s Presence Metadata Service (IMDS).
Initial attempts failed because the feature enforced an HTTPS URL, while IMDS uses HTTP. Undeterred, the researcher circumvented this by using a 302 redirect from an external HTTPS endpoint (via tools like ssrf.cvssadvisor.com) to the internal metadata URL. The server followed the redirect, but Azure blocked access without the “Metadata: true” header.
Further investigation revealed a solution: the authentication settings allowed custom “API keys”. Naming a “Metadata” with the value “true” inserted the required header. Success! GPT returned IMDS data, including an OAuth2 token for the Azure Management API (requested via /metadata/identity/oauth2/token?resource=https://management.azure.com/).
This token provided direct access to OpenAI’s cloud environment, allowing for enumeration or scaling of resources. The impact was severe. In cloud settings, such tokens could lead to a full-scale breach, as observed in previous Open Security penetration tests where SSRF led to remote code execution in hundreds of cases. For ChatGPT, there was a risk of leaking production secrets, although the researcher noted that this was not the most devastating they had found.
See also: 7 vulnerabilities in GPT-4o and GPT-5 allow 0-Click attacks

Immediately reported to OpenAI's Bugcrowd program , the vulnerability was given a high severity rating and received a quick patch. OpenAI confirmed the fix, preventing further exploitation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
