The National Information Technology Development Agency (NITDA) has identified loopholes in OpenAI’s latest large language models, which could expose users to data leakage risks.
In a tweet on its official X handle, the agency’s Computer Emergency Readiness and Response Team (CERRT.NG) highlighted that seven vulnerabilities were found in OpenAI’s GPT-4.0 and GPT-5 series models.
The team emphasised that the vulnerabilities allow attackers to manipulate ChatGPT via indirect prompt injections hidden in online content that appears harmless.
They elaborated that by planting malicious instructions in web pages, comments, or crafted URLs, ChatGPT can run unintended commands during search activities, normal browsing, and summarisation.
CERRT added that another pressing issue is the tendency toward long-term manipulation, in which ChatGPT’s memory is so affected that injected malicious prompts affect future output.
To address this issue, CERRT recommended that users and organisations limit or disable ChatGPT’s browsing and summarisation features on untrusted websites.
In addition, GPT-4.0 and GPT-5 models should be updated regularly to ensure known vulnerabilities are patched.

Leave feedback about this