Security researchers discovered a vulnerability in OpenAI’s public help forum that could allow attackers to gain control of the platform. The forum is operated using software from the Discourse platform.
The vulnerability was reported to the relevant companies, which coordinated efforts to address the issue and deploy a security patch.
OpenAI confirmed that the flaw was fixed within around 14 hours of being reported. The company also awarded the researchers a $6,500 bug bounty for identifying and reporting the vulnerability.
The security researchers said they initially used an advanced AI model to identify and exploit the software flaw, although the process was not consistently successful.
Following the release of a newer version of the AI model, the researchers said it was able to generate a functioning exploit in approximately three hours, highlighting the increasing ability of AI systems to assist with complex cybersecurity research.
The researchers did not use a more advanced AI model designed specifically for cybersecurity, which is reportedly restricted to a limited number of vetted cyber-defence organisations.
According to the researchers, the underlying software vulnerability was not exclusive to OpenAI and could potentially affect products and services operated by other major technology companies that use similar software.
The researchers said they are continuing to examine other companies’ systems for similar security weaknesses.
The incident highlights growing concerns within the cybersecurity industry that increasingly capable AI systems could reduce the time, cost and technical expertise required to identify and exploit sophisticated software vulnerabilities.