from Hacker News

ChatGPT Plugin Flaw – attackers could access private GitHub repos of others

by MorL on 3/15/24, 1:18 PM with 2 comments

  • by aviCC on 3/15/24, 1:28 PM

    Technical details: "The plugin does not authenticate the request, which means that the attacker can insert another memberId (aka the victim) and get a code that represents the victim. With that code, he can use ChatGPT and access the GitHub of the victim."