{"id":"e76106d3-3796-492b-9997-569446b51b72","engagementId":"3a92991c-f94a-4f00-8053-49418ab93629","data":{"brief":{"id":"9ce996a5-3edc-477f-ba5d-8c4ed4eb8eec","name":"OpenAI","tagline":"OpenAI is an AI research and deployment company. Our mission is to ensure that artificial general intelligence benefits all of humanity.","description":"\u003cp\u003eSecurity is essential to OpenAI's mission. We appreciate the contributions of ethical hackers who help us uphold high privacy and security standards for our users and technology. This policy (based on disclose.io) outlines our definition of good faith regarding the discovery and reporting of vulnerabilities, and clarifies what you can expect from us in return.\u003c/p\u003e\n\n\u003cp\u003eThe initial priority rating for most findings will use the Bugcrowd Vulnerability Rating Taxonomy. However, vulnerability priority and reward may be modified based on likelihood or impact at OpenAI's sole discretion. In cases of downgraded issues, researchers will receive a detailed explanation.\u003c/p\u003e\n\n\u003ch2\u003eExpectations\u003c/h2\u003e\n\n\u003cp\u003eAs part of this policy, we commit to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eProvide Safe Harbor protection, as outlined below, for vulnerability research conducted according to these guidelines.\u003c/li\u003e\n\u003cli\u003eCooperate with you in understanding and validating your report, ensuring a prompt initial response to your submission.\u003c/li\u003e\n\u003cli\u003eRemediate validated vulnerabilities in a timely manner.\u003c/li\u003e\n\u003cli\u003eAcknowledge and credit your contribution to improving our security, if you are the first to report a unique vulnerability that leads to a code or configuration change.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cp\u003eTo help us distinguish between good-faith hacking and malicious attacks, you must follow these rules:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou are authorized to perform testing in compliance with this policy.\u003c/li\u003e\n\u003cli\u003eFollow this policy and any other relevant agreements. In case of inconsistency, this policy takes precedence.\u003c/li\u003e\n\u003cli\u003ePromptly report discovered vulnerabilities.\u003c/li\u003e\n\u003cli\u003eRefrain from violating privacy, disrupting systems, destroying data, or harming user experience.\u003c/li\u003e\n\u003cli\u003eUse OpenAI's Bugcrowd program for vulnerability-related communication.\u003c/li\u003e\n\u003cli\u003eKeep vulnerability details confidential until authorized for release by OpenAI's security team, which aims to provide authorization within 90 days of report receipt.\u003c/li\u003e\n\u003cli\u003eTest only in-scope systems and respect out-of-scope systems.\u003c/li\u003e\n\u003cli\u003eDo not access, modify, or use data belonging to others, including confidential OpenAI data. If a vulnerability exposes such data, stop testing, submit a report immediately, and delete all copies of the information.\u003c/li\u003e\n\u003cli\u003eInteract only with your own accounts, unless authorized by OpenAI.\u003c/li\u003e\n\u003cli\u003eDisclosure of vulnerabilities to OpenAI must be unconditional. Do not engage in extortion, threats, or other tactics to elicit a response under duress. OpenAI denies Safe Harbor for vulnerability disclosure conducted under such circumstances.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003e\u003cstrong\u003eSTOP. READ THIS. DO NOT SKIM OVER IT.\u003c/strong\u003e\u003c/h1\u003e\n\n\u003ch1\u003eModel Issues\u003c/h1\u003e\n\n\u003cp\u003eOpenAI is committed to \u003ca href=\"https://openai.com/blog/our-approach-to-ai-safety\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003emaking AI safe and useful for everyone\u003c/a\u003e. Before releasing a new system, we thoroughly test it, get expert feedback, improve its behavior, and set up safety measures. While we work hard to prevent risks, we can't predict every way people will use or misuse our technology in the real world. Safety and abuse issues can be reported to our \u003ca href=\"https://bugcrowd.com/engagements/openai-safety\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSafety Bug Bounty\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eSome model safety issues, such as jailbreaks, do not fit well within a bug bounty program, as they are not individual, discrete bugs that can be directly fixed. Addressing these issues often involves substantial research and a broader approach. To ensure that these concerns are properly addressed, please report them using the \u003ca href=\"https://openai.com/form/model-behavior-feedback\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eModel Behavior Feedback form\u003c/a\u003e, rather than submitting them through the bug bounty program. Reporting them in the right place allows our researchers to use these reports to improve the model.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eIssues related to the content of model prompts and responses are strictly out of scope for the Security and Safety Bug Bounty programs, and will not be rewarded\u003c/strong\u003e unless they have an additional directly verifiable security impact on an in-scope service (described below).\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eExamples of safety issues which are out of scope:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eJailbreaks/Safety Bypasses (e.g. DAN and related prompts)\u003c/li\u003e\n\u003cli\u003eGetting the model to say bad things to you\u003c/li\u003e\n\u003cli\u003eGetting the model to tell you how to do bad things\u003c/li\u003e\n\u003cli\u003eGetting the model to write malicious code for you\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eModel Hallucinations are also out of scope:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGetting the model to pretend to do bad things\u003c/li\u003e\n\u003cli\u003eGetting the model to pretend to give you answers to secrets\u003c/li\u003e\n\u003cli\u003eGetting the model to pretend to be a computer and execute code\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eSandboxed Python code executions are also out of scope:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eCode execution from within our sandboxed Python code interpreter is out of scope. This is an intended product feature.\u003cbr\u003e\nWhen the model executes Python code, it does so within this sandbox. If you believe you've achieved RCE outside this sandbox, your report must show that the output of the following commands differs from these indicators.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ccode\u003euname -a\u003c/code\u003e:  The following output, specifically the 2016 kernel, indicates you are inside the sandbox:\n\u003ccode\u003eLinux 9d23de67-3784-48f6-b935-4d224ed8f555 4.4.0 #1 SMP Sun Jan 10 15:06:54 PST 2016 x86_64 x86_64 x86_6\u003c/code\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ccode\u003ewhoami\u003c/code\u003e: An output of \u003cstrong\u003e\u003ccode\u003esandbox\u003c/code\u003e\u003c/strong\u003e confirms you are inside the sandbox.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAgent Mode Sandbox\u003c/h2\u003e\n\n\u003cp\u003eSimilarly, code execution from within Agent Mode is out of scope, as it occurs within a separate, contained environment. To validate a potential RCE outside the Agent sandbox, your report must include the output of the commands below, and the results must differ from these indicators.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eInitial Indicators:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ccode\u003euname -a\u003c/code\u003e : The following kernel version (and the year 2025) indicates you are inside the sandbox:\n\u003ccode\u003eLinux 454b19a9c4b5 6.12.13 #1 SMP Thu Mar 13 11:34:50 UTC 2025 x86_64 GNU/Linux\u003c/code\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e•\u003ccode\u003ewhoami\u003c/code\u003e : An output of \u003cstrong\u003e\u003ccode\u003eoai\u003c/code\u003e\u003c/strong\u003e confirms you are inside the sandbox.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDefinitive Network Check:\u003c/strong\u003e You are inside the sandbox if an IP address from \u003ccode\u003ehostname -I\u003c/code\u003e matches the IP for \u003ccode\u003eterminal. local\u003c/code\u003e or \u003ccode\u003echrome. local\u003c/code\u003e in \u003ccode\u003e/etc/hosts\u003c/code\u003e.\u003c/p\u003e\n\n\u003cp\u003e• Example:\u003cbr\u003e\n\u003ccode\u003e$ hostname -I\u003cbr\u003e\n172.18.0.19 172.30.1.35\u003cbr\u003e\n$ cat /etc/hosts | grep \"\\. local\"\u003cbr\u003e\n172.30.1.34 chrome. local\u003cbr\u003e\n172.30.1.35 terminal.local\u003cbr\u003e\n172.30.1.36 proxy. local\u003c/code\u003e\u003cbr\u003e\n• In this case, the shared IP \u003ccode\u003e172.30.1.35\u003c/code\u003e confirms the execution is sandboxed.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eContainer Tool Sandbox (GPT-5 Models)\u003c/h2\u003e\n\n\u003cp\u003eCertain models may use a \u003ccode\u003econtainer\u003c/code\u003e tool for shell execution. This environment is also sandboxed and out of scope. This tool can be identified by the user appearing as \u003ccode\u003eroot\u003c/code\u003e.\u003c/p\u003e\n\n\u003cp\u003eThis is \u003cstrong\u003enot\u003c/strong\u003e a privilege escalation. The \u003ccode\u003eroot\u003c/code\u003e user has no special privileges outside of this container, which runs within a highly restrictive \u003cstrong\u003eg Visor sandbox\u003c/strong\u003e with \u003cstrong\u003eno external network\u003c/strong\u003e access. Reports demonstrating \u003ccode\u003eroot\u003c/code\u003e access in this specific environment are not valid.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eInside the sandbox you would also see \u003ccode\u003esandbox\u003c/code\u003e as the output of \u003ccode\u003ewhoami\u003c/code\u003e, and as the only user in the output of \u003ccode\u003eps\u003c/code\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNone of these issues may be reported through bugcrowd.\u003cbr\u003e\nNone of these issues will receive a monetary reward.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eFor model related issues, please report them here:\u003cbr\u003e\n\u003ca href=\"https://openai.com/form/model-behavior-feedback\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://openai.com/form/model-behavior-feedback\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eWe will provide Safe Harbor protection, as outlined below, for model issues research conducted in accordance with this policy. In some very limited cases, we may reward academic research related to model safety, the disclosure of model weights, training data, and related concerns. Please submit research papers to disclosure@openai.com for consideration.\u003c/p\u003e\n\n\u003ch1\u003e\u003cstrong\u003eSTOP. READ THIS. DO NOT SKIM OVER IT.\u003c/strong\u003e\u003c/h1\u003e\n\n\u003chr\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch3\u003eAccess to unreleased/private models\u003c/h3\u003e\n\n\u003cp\u003eWe will accept reports of attacks in which you are able to send requests to (and receive output from) an OpenAI model that is private or unreleased (in other words, it is not mentioned in our API documentation nor available in the model picker). These will be eligible for a bounty, with severity determined by the sensitivity of the model in question.\u003c/p\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eYou may test with your personal account or sign up for an additional testing account using your @bugcrowdninja.com email address. We prefer testing using this email address, but it is not mandatory.\u003c/p\u003e\n\n\u003cp\u003ePlease note that authorized testing does not exempt you from all of OpenAI's terms of service. Abusing the service may result in rate limiting, blocking, or banning. Automated vulnerability scanners may trigger these outcomes. If your account or IP is rate-limited or blocked, please wait for the block to expire; we cannot manually remove it. If your account is banned, contact support@bugcrowd.com to provide an explanation and request un-banning. We will only do this a limited number of times, at our discretion, and never for content violations. You will be removed from the program for repeated ban evasion.\u003c/p\u003e\n\n\u003cp\u003eYou will \u003cem\u003enot\u003c/em\u003e be reimbursed for any upgrades or purchases made on your account.\u003c/p\u003e\n\n\u003ch3\u003eApplication-layer prompt injection mitigations\u003c/h3\u003e\n\n\u003cp\u003eWe deploy various mitigations to prompt injection (a kind of vulnerability in which the AI model is misled into acting against the user's best interests by a third-party) both within our AI models, and within our consumer applications. We are interested in plausible attack chains that demonstrate low-interaction transfer of user data to a third-party within our applications including via prompt injection. Please note that such attacks must be grounded in the application layer; we will not accept submissions relating to mitigations within our models themselves. Feedback on model behaviour should be directed here: https://openai.com/form/chat-model-feedback\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eThe following are non-exhaustively out-of-scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eModel issues. See above.\u003c/li\u003e\n\u003cli\u003eAttacks that may degrade, disrupt, or negatively impact services or user experience (e.g., denial of service, brute force, password spraying, spam, fuzzing, specifically unless authorized by OpenAI's security team).\n\n\u003cul\u003e\n\u003cli\u003eThis includes brute forcing our APIs.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAttacks that aim to destroy or corrupt data not belonging to you.\u003c/li\u003e\n\u003cli\u003eAttacks stemming from stolen or leaked credentials.\u003c/li\u003e\n\u003cli\u003eIntentional access to data or information not belonging to you beyond the minimum necessary to demonstrate the vulnerability.\u003c/li\u003e\n\u003cli\u003ePhysical, social engineering, phishing, or electronic attacks against OpenAI personnel, offices, wireless networks, or property.\u003c/li\u003e\n\u003cli\u003eAny attacks on systems not explicitly mentioned as in-scope.\u003c/li\u003e\n\u003cli\u003eAttacks related to email servers, protocols, security (e.g., SPF, DMARC, DKIM), or spam.\u003c/li\u003e\n\u003cli\u003eReports of insecure SSL/TLS ciphers without a working proof-of-concept.\u003c/li\u003e\n\u003cli\u003eReports of missing HTTP headers (e.g., lack of HSTS) without a working proof-of-concept.\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eReports of server error messages without proof of an exploit.\u003c/li\u003e\n\u003cli\u003eVulnerabilities impacting only old/end-of-life browsers/plugins.\u003c/li\u003e\n\u003cli\u003eReports relating to server version strings.\u003c/li\u003e\n\u003cli\u003eReports about verification tokens in \u003ccode\u003e./well-known/ai-plugin.json\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttempts to get malicious code executed by posting internal package names (or close replicas of them) in public repos.\u003c/li\u003e\n\u003cli\u003eSandboxed code execution from the ChatGPT Python code interpreter product feature.\u003c/li\u003e\n\u003cli\u003eDiscovery of names or references to unreleased products/features\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eSpecific examples that are out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDomains (such as \u003ccode\u003epay.openai.com\u003c/code\u003e) which are CNAME'd to stripe. Please report issues to \u003ca href=\"https://hackerone.com/stripe\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003etheir program\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eDomains that are CNAME'd to other active third party service providers like \u003ccode\u003ecommunity.openai.com\u003c/code\u003e. Unused subdomain takeovers are still in scope.\u003c/li\u003e\n\u003cli\u003eChanging your password may not invalidate all Auth tokens and API Keys.\u003c/li\u003e\n\u003cli\u003eThe ability to add other users to your organization without their permission.\u003c/li\u003e\n\u003cli\u003eAccount deletion does not require password.\u003c/li\u003e\n\u003cli\u003eAPI Keys have broad permissions and capabilities.\u003c/li\u003e\n\u003cli\u003eYou can make more API keys than the cap.\u003c/li\u003e\n\u003cli\u003eCookies can be transferred from one browser to another.\u003c/li\u003e\n\u003cli\u003eChatGPT will display images from other domains.\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eExcept\u003c/strong\u003e where loading the image transmits sensitive user data to a third-party without their consent; see \"Application-layer prompt injection mitigations\" above.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThe expected functionality of OpenGraph Tags (which request information from a rendered url in order to show a preview).\u003c/li\u003e\n\u003cli\u003eWeird model behavior following \"special\" or \"bugged\" tokens.\u003c/li\u003e\n\u003cli\u003eCertain overlong inputs can cause ChatGPT to produce what appear to be random or other people's answers.\n\n\u003cul\u003e\n\u003cli\u003eThese are a specific form of model hallucination caused by a bug in ChatGPT which causes the model to be asked for a completion with a missing query.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eReports that you can create accounts using online SMS services, without a detailed and specific description of a different security issue.\u003c/li\u003e\n\u003cli\u003eMethods to bypass IP blocks or geoblock by changing your IP or using a VPN.\u003c/li\u003e\n\u003cli\u003eMethods to bypass cloudflare on api.openai.com.\u003c/li\u003e\n\u003cli\u003eMethods to bypass the \u003ccode\u003eChatGPT is at capacity\u003c/code\u003e page.\u003c/li\u003e\n\u003cli\u003eMethods to emulate a browser to bypass captchas.\u003c/li\u003e\n\u003cli\u003eWebsites which are not owned and operated by OpenAI, including \u003ccode\u003eai.com\u003c/code\u003e and \u003ccode\u003eopen.ai\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePhishing websites, proxies for ChatGPT, discord bots, and other \"free\" websites which provide access the product.\u003c/li\u003e\n\u003cli\u003eBrowser plugins that modify the behavior of ChatGPT.\u003c/li\u003e\n\u003cli\u003eThe fact that you can share model presets by link on \u003ccode\u003eplatform.openai.com/playground\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eIssues related to changing the email address sent to intercom.\u003c/li\u003e\n\u003cli\u003eIssues related to billing lagging behind requests.\u003c/li\u003e\n\u003cli\u003eMost issues relating to API rate limiting or API quota enforcement unless the bug allows complete bypass. \n\n\u003cul\u003e\n\u003cli\u003eWe reward submissions that demonstrate a meaningful bypass of OpenAI rate limits or platform controls that enables sustained usage at significant scale beyond intended limits. Issues that don't scale to the order of hundreds of requests beyond enforced rate limits (e.g., one-off or low-volume bypasses) are considered out of scope for financial reward.\u003c/li\u003e\n\u003cli\u003eOut of scope: temporarily exceeding the API requests-per-minute limit, the tokens-per-minute limit, or the hard spending cap.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThe fact that you can send shell commands to the Code Interpreter VM instance.\u003c/li\u003e\n\u003cli\u003eVulnerabilities in most of our dormant open source projects. \n\n\u003cul\u003e\n\u003cli\u003eWe welcome reports (and patches) but typically will only reward for security issues with demonstrated impact in our actively maintained projects.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eIssues that require excessive user cooperation or unlikely social engineering to trigger, such as loading malicious content from external websites, self XSS through the browser debug pane, disabling browser security features, sending the attacker information out of band, etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCVE Assignment\u003c/h2\u003e\n\n\u003cp\u003eOpenAI's CVE Assignment Policy explains how we handle vulnerability reports as a CVE Numbering Authority (CNA). This policy describes which types of security issues are in scope, how to submit reports, how CVE identifiers are assigned, and how we coordinate public disclosure. \u003ca href=\"https://openai.com/policies/openai-cve-assignment-policy/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eLearn more\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eOpenAI will not threaten or bring any legal action against anyone who makes a good faith effort to comply with this bug bounty policy. This includes any claim under the DMCA for circumventing technological measures to protect the services and applications eligible under this policy.\u003c/p\u003e\n\n\u003cp\u003eAs long as you comply with this policy:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe consider your security research to be \"authorized\" under the Computer Fraud and Abuse Act (and/or similar state laws), and\u003c/li\u003e\n\u003cli\u003eWe waive any restrictions in our applicable Terms of Use and Usage Policies that would prohibit your participation in this policy, but only for the limited purpose of your security research under this policy.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOpenAI systems and services may be interconnected with third-party systems and services. If you submit a report through our bug bounty program that affects a third party service, we will limit what we share with the affected third party. Please understand that, while we can authorize your research on OpenAI’s systems and services, we cannot authorize your efforts on third-party products or guarantee they won’t pursue legal action against you. That said, if legal action is initiated by a third party against you because of your participation in this bug bounty program, and you have complied with our bug bounty policy, we will take steps to make it known that your actions were conducted in compliance with this policy. This is not, and should not be understood as, any agreement on our part to defend, indemnify, or otherwise protect you from any third party action based on your actions.\u003c/p\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf you have concerns or are unsure whether your security research aligns with this policy, please contact support@bugcrowd.com before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"2ba1f152-693c-4874-a1db-806cf9e66610","name":"API Targets","targets":[{"id":"0fda723f-ec1e-47a5-bd5a-37df666b2766","uri":"https://api.openai.com","name":"api.openai.com","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"672eb029-eaa5-471e-b2f2-96012cb43331","sortOrder":0},"sortOrder":0,"tags":[{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"0fda723f-ec1e-47a5-bd5a-37df666b2766"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"0fda723f-ec1e-47a5-bd5a-37df666b2766"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"ec25947d-ba46-462e-9963-febf3b6c74ef","p1MaxCents":650000,"p1MinCents":200000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":10000000},"descriptionHtml":"\u003cp\u003eThe following services and applications are in-scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe OpenAI APIs.\u003c/li\u003e\n\u003cli\u003ePublic cloud resources or infrastructure involved in serving the OpenAI API, including:\n\n\u003cul\u003e\n\u003cli\u003ecloud storage accounts (e.g., Azure data blobs).\u003c/li\u003e\n\u003cli\u003ecloud compute servers (e.g., Azure virtual machines).\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAs noted earlier, model safety and content issues are not eligible for reward in any of the categories.\u003c/p\u003e","rewardRangeData":{"1":{"min":2000,"max":6500},"2":{"min":1000,"max":2000},"3":{"min":500,"max":1000},"4":{"min":200,"max":500},"5":{"min":null,"max":null},"programMax":100000},"recentChangeFlags":null},{"id":"831be957-0b35-4096-91a2-636ad502702e","name":"ChatGPT","targets":[{"id":"fb20df1f-3c20-4bc4-bcf6-054fc9ac5061","uri":"https://chat.openai.com","name":"ChatGPT","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"07022e49-7336-4337-a2ac-111fb6946452","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"c9f60107-e82c-48f3-aeb3-c2059a394a01","uri":"https://chat.openai.com","name":"ChatGPT Plugins","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"36f1dbbc-c503-4f08-a9b5-bc42f0547f46","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"c9f60107-e82c-48f3-aeb3-c2059a394a01"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"c9f60107-e82c-48f3-aeb3-c2059a394a01"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"c9f60107-e82c-48f3-aeb3-c2059a394a01"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"ec25947d-ba46-462e-9963-febf3b6c74ef","p1MaxCents":650000,"p1MinCents":200000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":10000000},"descriptionHtml":"\u003cp\u003eChatGPT is in scope, including ChatGPT Plus, logins, subscriptions, OpenAI-created plugins (e.g. Browsing, Code Interpreter), plugins you create yourself, and all other functionality. If you have a conversation with ChatGPT to demonstrate your issue, please include the conversation ID (the URL that appears in your address bar when the conversation is open).\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNOTE: You are not authorized to conduct security testing on plugins created by other people.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eExamples of things we are interested in:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eStored or Reflected XSS\u003c/li\u003e\n\u003cli\u003eCSRF\u003c/li\u003e\n\u003cli\u003eSQLi\u003c/li\u003e\n\u003cli\u003eAuthentication Issues\u003c/li\u003e\n\u003cli\u003eAuthorization Issues\u003c/li\u003e\n\u003cli\u003eData Exposure\u003c/li\u003e\n\u003cli\u003ePayments issues\u003c/li\u003e\n\u003cli\u003eMethods to bypass cloudflare protection by sending traffic to endpoints that are not protected by cloudflare\u003c/li\u003e\n\u003cli\u003eAbility to run queries on pre-release or private models\u003c/li\u003e\n\u003cli\u003eOpenAI created plugins:\n\n\u003cul\u003e\n\u003cli\u003eBrowsing\u003c/li\u003e\n\u003cli\u003eCode Interpreter\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eSecurity issues with the plugin creation system:\n\n\u003cul\u003e\n\u003cli\u003eOutputs which cause the browser application to crash\u003c/li\u003e\n\u003cli\u003eCredential security\u003c/li\u003e\n\u003cli\u003eOAuth\u003c/li\u003e\n\u003cli\u003eSSRF\u003c/li\u003e\n\u003cli\u003eMethods to cause the plugin service to make calls to unrelated domains from where the manifest was loaded\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e if your account is approved to create plugins, you may create and test your own plugins, their functionality, and their interactions with ChatGPT. You may \u003ca href=\"https://openai.com/waitlist/plugins\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esign up for the waitlist\u003c/a\u003e, but OpenAI and bugcrowd cannot get you off the waitlist, do not ask. You may not perform security testing on plugins created by other people (e.g. Plugins in the plugin store).\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003cp\u003eFor model related issues, please use the reporting channels discussed earlier. \u003cbr\u003e\n\u003cstrong\u003eModel issues are strictly out of scope and will not be rewarded.\u003c/strong\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":2000,"max":6500},"2":{"min":1000,"max":2000},"3":{"min":500,"max":1000},"4":{"min":200,"max":500},"5":{"min":null,"max":null},"programMax":100000},"recentChangeFlags":null},{"id":"4422957f-6f6b-48cd-a0ca-0b02c9bf046c","name":"Third Party Corporate Targets","targets":[{"id":"fa4bd439-8067-406e-bebf-638551ce1632","uri":"","name":"Third Party Targets","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a5770d58-afc0-41e6-89f6-ee7f7638f969","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"6bd2bb88-1669-4eae-94e8-d4738e183c75","p1MaxCents":250000,"p1MinCents":100000,"p2MaxCents":100000,"p2MinCents":50000,"p3MaxCents":50000,"p3MinCents":20000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":500000},"descriptionHtml":"\u003cp\u003eThis target group consists of confidential OpenAI corporate information that may be exposed through third parties. Some examples of the types vendors which would qualify in this category include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGoogle Workspace\u003c/li\u003e\n\u003cli\u003eAsana, Trello, Jira, Monday.com\u003c/li\u003e\n\u003cli\u003eNotion, Confluence, Evernote\u003c/li\u003e\n\u003cli\u003eIntercom, Hubspot, Zendesk\u003c/li\u003e\n\u003cli\u003eStripe, Airbase, Navan\u003c/li\u003e\n\u003cli\u003eMode, Charthop, Looker\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eYou are not authorized to perform additional security testing against these companies.\u003c/strong\u003e Testing is limited to looking for confidential OpenAI information while following all laws and applicable terms of service. These companies are examples, and OpenAI does not necessarily do business with them.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eReports with multiple documents that share a root cause may be paid out at higher rates\u003c/strong\u003e. Individual documents will typically be accepted at P4 or P5, which does not qualify for a monetary reward. For documents that contain particularly sensitive information, the reward category may be increased on a case-by-case basis. This will be rare.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCorporate target submissions must include detailed information to help us understand your discovery process.\u003c/strong\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":1000,"max":2500},"2":{"min":500,"max":1000},"3":{"min":200,"max":500},"4":{"min":null,"max":null},"5":{"min":null,"max":null},"programMax":5000},"recentChangeFlags":null},{"id":"238c4f73-4fbe-4f1b-93f3-1e4167c11c51","name":"OpenAI API Keys","targets":[{"id":"9028bfcd-caaa-44a7-a3ce-53d9cb2c89d7","uri":"","name":"OpenAI API Keys","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8ed9d76f-d477-4578-8ba5-593e2afb5c6e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"c02182db-904d-42ac-9061-f9b697e01937","p1MaxCents":250000,"p1MinCents":25000,"p2MaxCents":null,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAPI Key Security Initiative for OpenAI\u003c/p\u003e\n\n\u003cp\u003eOur customers occasionally post their API keys on the internet. We need your help to keep them safe. Once a month, we will rank all submissions and award a bonus through the Bugcrowd platform to the researcher with the most impactful submission. Only the first submission of a given key will be considered. As a note, we will reach out to researchers that qualify for the reward. If you do not hear from us, it is safe to assume you did not win the current month. Please do not reach out to the Bugcrowd support team around the processing of these keys\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eIMPORTANT: DO NOT SEND KEYS THROUGH BUGCROWD. Please report found API keys using the OpenAI API Key Bug Bounty Submission Form. Submissions to Bugcrowd will be marked as out-of-scope and will result in a point deduction.\u003c/li\u003e\n\u003cli\u003eDo not post or share OpenAI API keys online.\u003c/li\u003e\n\u003cli\u003eValid OpenAI API Keys have the prefix \u003ccode\u003esk-\u003c/code\u003e or \u003ccode\u003esess-\u003c/code\u003e Any submission that does not adhere to this format will be rejected.\u003c/li\u003e\n\u003cli\u003eAdditional Things to Avoid:\n\n\u003cul\u003e\n\u003cli\u003ePlease don\u0026#39;t submit the same keys repeatedly.\u003c/li\u003e\n\u003cli\u003eDon\u0026#39;t create keys just to submit them.\u003c/li\u003e\n\u003cli\u003eDon\u0026#39;t submit keys one-by-one - we can handle them in bulk.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eCreating multiple accounts or generating many API keys for a single account is a violation of our terms. This may result in account suspension.\nPlay nicely. We keep a close eye on everything. Make sure that you act responsibly.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eThank you for your assistance!\u003c/p\u003e\n\n\u003cp\u003eThis form is temporary - we will create an API for this soon.\u003c/p\u003e\n\n\u003cp\u003eSubmit all findings here:\u003cbr\u003e\n\u003ca href=\"https://forms.gle/h8bQ5YKWzXb8FtrQ8\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOpenAI API Key Bug Bounty Submission\u003c/a\u003e\u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003ch2\u003eIMPORTANT\u003c/h2\u003e\n\n\u003cp\u003eDo not submit API keys to bugcrowd. The submission will be marked as out of scope and you will lose points. You must submit through the form.\u003c/p\u003e\n\u003c/blockquote\u003e","rewardRangeData":{"1":{"min":250,"max":2500},"2":{"min":null,"max":null},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"24605099-2368-4427-9027-1e393c15c700","name":"OpenAI Research Org","targets":[{"id":"406c1b90-cd17-4ee3-8ffd-b99a9f18b6ac","uri":"https://*.openai.org","name":"https://openai.org","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f9928b12-0573-4415-afd6-fcd027f5dbdd","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"406c1b90-cd17-4ee3-8ffd-b99a9f18b6ac"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"406c1b90-cd17-4ee3-8ffd-b99a9f18b6ac"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"406c1b90-cd17-4ee3-8ffd-b99a9f18b6ac"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"406c1b90-cd17-4ee3-8ffd-b99a9f18b6ac"}],"recentChangeFlags":null},{"id":"1652d360-2e60-4d49-9a61-52c3c1a4c97c","uri":"https://*.openai.org","name":"*.openai.org","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5b49b2f0-2325-4fa7-8aa8-75783a7f3843","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1652d360-2e60-4d49-9a61-52c3c1a4c97c"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"1652d360-2e60-4d49-9a61-52c3c1a4c97c"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"1652d360-2e60-4d49-9a61-52c3c1a4c97c"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"3aef2b01-620c-4012-93b4-a25ff21f9468","p1MaxCents":350000,"p1MinCents":125000,"p2MaxCents":125000,"p2MinCents":60000,"p3MaxCents":60000,"p3MinCents":20000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":10000000},"descriptionHtml":"\u003cp\u003eWebsites, services, and APIs operated by or for the OpenAI research organization. This category includes some websites which are subdomains of \u003ccode\u003eopenai.com\u003c/code\u003e, but these targets will generally be found at \u003ccode\u003eopenai.org\u003c/code\u003e and subdomains.\u003c/p\u003e","rewardRangeData":{"1":{"min":1250,"max":3500},"2":{"min":600,"max":1250},"3":{"min":200,"max":600},"4":{"min":null,"max":null},"5":{"min":null,"max":null},"programMax":100000},"recentChangeFlags":null},{"id":"f4c43402-4eed-4278-ad55-2a56b55cfebb","name":"Other OpenAI Targets","targets":[{"id":"fcb4d4b4-62c6-430b-96e3-37bde84f5456","uri":"https://openai.com/","name":"openai.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1b6b451b-a319-4e0a-a8c7-ec4762993407","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fcb4d4b4-62c6-430b-96e3-37bde84f5456"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"fcb4d4b4-62c6-430b-96e3-37bde84f5456"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"fcb4d4b4-62c6-430b-96e3-37bde84f5456"}],"recentChangeFlags":null},{"id":"75fe2658-39e9-4aeb-9add-5a26c0c8ac4d","uri":"","name":"*.openai.com","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"983af1d6-54fc-4bd2-a616-521ae4599755","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"75fe2658-39e9-4aeb-9add-5a26c0c8ac4d"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"75fe2658-39e9-4aeb-9add-5a26c0c8ac4d"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"75fe2658-39e9-4aeb-9add-5a26c0c8ac4d"}],"recentChangeFlags":null},{"id":"4547f931-ae0e-431a-b1fc-82d979b5c39e","uri":"https://platform.openai.com/playground","name":"Developer Platform Playground","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b2ee1e43-f7b4-486b-8589-0cd1634c8946","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4547f931-ae0e-431a-b1fc-82d979b5c39e"}],"recentChangeFlags":null},{"id":"76d3a23b-b7f1-49bc-980f-86d0b14516ef","uri":"","name":"Other","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f16fc717-6117-4bf7-8538-995dcdce4548","sortOrder":0},"sortOrder":0,"tags":[{"id":"d14cf1dd-8069-48ef-9a2b-779bf3a066f9","name":"Artificial Intelligence","targetId":"76d3a23b-b7f1-49bc-980f-86d0b14516ef"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":5,"description":null,"rewardRange":{"id":"d3991049-fc46-4a67-8c23-28fe12fca7eb","p1MaxCents":250000,"p1MinCents":125000,"p2MaxCents":125000,"p2MinCents":60000,"p3MaxCents":60000,"p3MinCents":20000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThis target group includes:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe OpenAI.com website.\u003c/li\u003e\n\u003cli\u003eThe OpenAI Developer Documentation.\u003c/li\u003e\n\u003cli\u003eThe Developer playground.\u003c/li\u003e\n\u003cli\u003eAny other Internet-facing infrastructure operated by OpenAI and not specified in another target.\u003c/li\u003e\n\u003cli\u003eAny other public cloud resources or infrastructure operated by OpenAI.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":1250,"max":2500},"2":{"min":600,"max":1250},"3":{"min":200,"max":600},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"2911713b-d052-4154-a30b-fe7fd09fe33a","name":"Codex","targets":[{"id":"bb382f87-b985-44ce-9662-9e0baa640bc2","uri":"","name":"Codex Desktop","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a5be9e5f-b6d6-4d48-8b10-3ea2abb9de00","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":8,"description":null,"rewardRange":{"id":"f343b6d2-5c64-4222-b126-af5f924f5fbb","p1MaxCents":150000,"p1MinCents":50000,"p2MaxCents":50000,"p2MinCents":25000,"p3MaxCents":25000,"p3MinCents":10000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":10000000},"descriptionHtml":"\u003cp\u003eThis program covers Codex’s supported CLI, web, and desktop surfaces, including the built-in browser in the \u003ca href=\"https://help.openai.com/en/articles/20001277-using-the-built-in-browser-in-the-chatgpt-desktop-app\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eChatGPT desktop app\u003c/a\u003e as well as the \u003ca href=\"https://chromewebstore.google.com/detail/chatgpt/hehggadaopoacecdllhhajmbjkdcmajg\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eChatGPT Chrome extension\u003c/a\u003e (extension ID \u003ccode\u003ehehggadaopoacecdllhhajmbjkdcmajg\u003c/code\u003e). Scope also includes the OpenAI-controlled software that connects the desktop app, browser, and extensions, controls the browser, or enforces applicable security restrictions.\u003c/p\u003e\n\n\u003ch2\u003eEligibility and supported configurations\u003c/h2\u003e\n\n\u003cp\u003eReports must reproduce on a current, supported release in a supported configuration. Features listed in the Codex CLI \u003ccode\u003e/experimental\u003c/code\u003e menu are not eligible for rewards, whether enabled through the menu or through \u003ccode\u003econfig.toml\u003c/code\u003e.\u003c/p\u003e\n\n\u003cp\u003eYou may test any current, documented, supported configuration. Choosing unrestricted execution, disabling the protection at issue, or explicitly granting the capability you are testing is not, by itself, a bypass. You may still test any other security restriction that applies to that supported configuration, including an enforced administrator restriction.\u003c/p\u003e\n\n\u003ch2\u003eIn scope\u003c/h2\u003e\n\n\u003cp\u003eWe are interested in software defects that let a less-privileged attacker bypass a security restriction enforced by Codex, its browser, the extension, or another OpenAI-controlled component. Persuading a model to misuse access it already has does not satisfy this requirement, even when data is disclosed or an unwanted action occurs.\u003c/p\u003e\n\n\u003cp\u003eAttacker-controlled content, including prompt injection, can be part of an eligible report only when it exploits a separate, demonstrable security-boundary flaw in an in-scope OpenAI product or OpenAI-controlled integration.\u003c/p\u003e\n\n\u003ch3\u003eCodex sandbox bypass or escape\u003c/h3\u003e\n\n\u003cp\u003eA sandbox-bypass report must show that execution exceeds a restriction enforced by the active, supported configuration. Examples include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFilesystem boundaries:\u003c/strong\u003e Writing outside the session’s authorized locations; making unauthorized changes to protected files, repositories, credentials, approvals, or application state; or accessing operating-system resources blocked by the active policy.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNetwork boundaries:\u003c/strong\u003e Making an outbound connection that the active sandbox or product policy blocks.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProcess or OS boundaries:\u003c/strong\u003e Starting a process that the active policy prohibits, obtaining a more privileged operating-system identity, accessing protected system resources beyond the session’s authority, or escaping an enforced process, account, browser, or operating-system boundary.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eA file read allowed by the active execution policy is not a sandbox escape. A separate flaw may still qualify if it bypasses a browser security restriction or an enforced rule on who may access, change, or receive the file. For example, a browser or extension flaw may let an unauthorized website obtain or upload it.\u003c/p\u003e\n\n\u003cp\u003eBrowser access and command execution have separate security restrictions. Ordinary browser network access does not, by itself, bypass the command-execution sandbox.\u003c/p\u003e\n\n\u003ch3\u003eIn-app browser and browser extension\u003c/h3\u003e\n\n\u003cp\u003eExamples include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eBrowser, extension, or application compromise:\u003c/strong\u003e Escaping an enforced renderer, browser, extension, application, or operating-system boundary; impersonating a trusted origin, extension, or caller; or abusing browser-to-extension or extension-to-app communication to reach protected data, privileged functionality, or code execution.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCross-origin or cross-context access:\u003c/strong\u003e An implementation flaw in the browser, official extension, or OpenAI-controlled authorization code allows a website, renderer, or other restricted component to access an origin, frame, account, profile, or session beyond its granted permissions. Examples include a webpage bypassing the browser’s same-origin policy, or browser snapshot code exposing a denied cross-origin iframe because it fails to enforce the iframe’s origin check. Prompt injection that merely persuades an agent to use permissions it already has is out of scope even when information crosses origins or is disclosed; submit those reports to the separate Safety program.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSensitive browser data:\u003c/strong\u003e An implementation flaw exposes credentials, session data, private page content, browsing history, screenshots, or local files to a recipient not authorized to receive them.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFile, download, and network boundary violations:\u003c/strong\u003e Allowing attacker-controlled web content to read, upload, download, or modify local data beyond the permission actually granted; bypassing a restriction on a file transfer’s origin or destination, including a redirect to an origin denied by the active policy; or reaching a local service or network destination blocked by active policy.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRequired approvals and other security controls\u003c/h3\u003e\n\n\u003cp\u003eAcross all in-scope products, examples include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBypassing an approval, confirmation, or other product-enforced security control that the active configuration requires for a transaction, communication, account change, upload, download, or other protected action.\u003c/li\u003e\n\u003cli\u003eAccepting a forged, revoked, or expired approval; replaying a one-time approval; or applying a valid approval to the wrong actor, action, site, recipient, or context.\u003c/li\u003e\n\u003cli\u003eUsing attacker-controlled content or a restricted component to bypass an enforced project-trust, sandbox, browser, authorization, origin, account, profile, session, or destination restriction and obtain unauthorized execution, protected data, or a protected action.\u003c/li\u003e\n\u003cli\u003eBypassing a supported administrator-enforced restriction or using a capability that the user or administrator has disabled.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eA model choosing an action already permitted by those controls does not qualify. A missing prompt is not a bypass when the product does not require one for that action.\u003c/p\u003e\n\n\u003ch2\u003eOut of scope and non-rewardable findings\u003c/h2\u003e\n\n\u003cp\u003eThe following are out of scope or not independently bounty-eligible:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNormal browsing, valid cross-origin requests, declared extension permissions, an authorized connected profile, intentionally shared browser state, or actions and data access allowed by the active configuration, without a separate violation of an applicable security restriction.\u003c/li\u003e\n\u003cli\u003ePrompt injection, jailbreaks, hallucinations, misleading model output, or an agent misusing access or valid, applicable approvals it already has, when no separate security boundary in an in-scope OpenAI product or OpenAI-controlled integration is bypassed. This exclusion applies even if the agent leaks sensitive data or performs an unwanted action. Such model-behavior reports may instead be eligible under the separate Safety program.\u003c/li\u003e\n\u003cli\u003eSocial engineering, phishing, persuading someone to enter credentials, or convincing a user to approve an accurately described action, without a separate implementation flaw.\u003c/li\u003e\n\u003cli\u003eUser-installed malware, an already compromised device, root or administrator access, or unrestricted code already running with the affected user’s authority, unless the report also crosses a separate enforced product or privilege boundary.\u003c/li\u003e\n\u003cli\u003eIssues limited to third-party browsers, websites, extensions, tools, or dependencies without an independent OpenAI-specific security flaw.\u003c/li\u003e\n\u003cli\u003ePerformance issues, unsupported or obsolete product versions, speculative missing-hardening claims, and other non-security bugs.\u003c/li\u003e\n\u003cli\u003eDenial-of-service or resource-exhaustion attacks requiring sustained, disruptive, or large-scale traffic.\u003c/li\u003e\n\u003cli\u003eFeatures unavailable through a current supported release, authorized rollout, or testing path expressly identified by OpenAI. A documented, supported optional feature remains eligible for bypasses of restrictions that still apply.\u003c/li\u003e\n\u003cli\u003eBrowser, desktop, and extension UI findings: Visual impersonation, misleading origin displays, and similar UI-only findings in Codex’s in-app browser or first-party desktop and browser-extension interfaces are classified as P5 (Informational) unless they demonstrate P1 (Critical) security impact. Researchers may still submit P5 findings, but they are not eligible for monetary rewards, and OpenAI does not commit to a response or remediation timeline for them. Findings with P1 (Critical) impact remain eligible. Examples may include directly exposing sensitive data, remote code execution, or causing actions beyond the user’s authorized permissions; the demonstrated impact, not the type of behavior alone, determines severity.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eUpstream Chromium and Google Chrome\u003c/h3\u003e\n\n\u003cp\u003eVulnerabilities in upstream Chromium or Google Chrome that reproduce in an equivalent, unmodified upstream release are out of scope and should be reported to \u003ca href=\"https://bughunters.google.com/about/rules/chrome-friends/chrome-vulnerability-reward-program-rules\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGoogle’s Chrome Vulnerability Reward Program\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eA previously disclosed Chromium vulnerability may be eligible only if all three conditions are met:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eMore than seven calendar days have elapsed since Google published the corresponding Chrome Stable security fix.\u003c/li\u003e\n\u003cli\u003eNo fixed or effectively mitigated supported Codex production release has been published for the affected operating system and architecture.\u003c/li\u003e\n\u003cli\u003eThe report demonstrates a concrete High- or Critical-severity violation of an in-scope Codex security boundary in the latest publicly available supported release.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eA version number, CVE identifier, scanner result, or upstream proof of concept not reproduced against Codex is not sufficient. This exception applies only to Chromium bundled with the Codex desktop app; it does not apply to an independently installed browser used with an official OpenAI browser extension. Flaws introduced by OpenAI code, browser configuration, official extensions, or OpenAI-controlled product integrations remain in scope.\u003c/p\u003e\n\n\u003ch2\u003eTesting safely\u003c/h2\u003e\n\n\u003cp\u003eYou may use your own websites and ordinary supported workflows to demonstrate a security-boundary violation. Test only with accounts, devices, browser profiles, websites, and data that you own or are authorized to use. Do not test against third-party websites, accounts, profiles, extensions, or data without authorization. Stop once the issue is demonstrated. Do not access another person’s data, make real purchases, take destructive actions, disrupt services, or attack OpenAI personnel or unrelated third parties.\u003c/p\u003e\n\n\u003ch2\u003eSubmitting a report\u003c/h2\u003e\n\n\u003cp\u003eA finding must identify the attacker’s starting authority, the applicable security restriction, the protected resource or action, and the concrete unauthorized outcome.\u003c/p\u003e\n\n\u003cp\u003eInclude the affected product and version, operating system, active configuration, relevant permissions or approvals, and reproduction steps showing the unauthorized outcome. For a model-assisted exploit, identify the separate security control that fails in the product, bundled browser, or OpenAI-controlled integration.\u003c/p\u003e\n\n\u003cp\u003eWhen submitting a browser or extension issue, select the \u003cstrong\u003eCodex Desktop\u003c/strong\u003e target.\u003c/p\u003e","rewardRangeData":{"1":{"min":500,"max":1500},"2":{"min":250,"max":500},"3":{"min":100,"max":250},"4":{"min":50,"max":100},"5":{"min":null,"max":null},"programMax":100000},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"3a92991c-f94a-4f00-8053-49418ab93629","code":"openai","state":"in_progress","endsAt":null,"bountyId":"5a347e6e-cbbc-4c5f-8725-172a68154d90","startsAt":"2023-04-11T17:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/eee6/48ca/31319ece/3b82dca429ba76bf224abbec781356a8_OpenAI-black-monoblossom.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-04-11T17:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/openai","changelogs":"/engagements/openai/changelog","submissions":null,"announcements":"/engagements/openai/announcements","hallOfFame":"/engagements/openai/hall_of_fames","crowdstream":"/engagements/openai/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/openai/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=openai\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/openai/engagement_subscribers","engagementChangelogsUrl":"/engagements/openai/changelog","publishedAt":"2026-08-19T04:37:52.067Z","engagementChangelogUrl":"/engagements/openai/changelog/e76106d3-3796-492b-9997-569446b51b72","createUserFeedbacksUrl":"/engagements/openai/feedbacks","engagementCrowdstreamUrl":"/engagements/openai/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}