OpenAI Sandbox Escape Flaw Allowed Free Access to Paid AI Models Without an API Key

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Security researcher Oliver Fish says he found an OpenAI sandbox escape that let him request paid AI models without an API key or an account. A screenshot shared online shows OpenAI awarding $300 for a report titled “Unauthenticated Sandbox Escape Enables Access to Internal OpenAI Responses API.”

The issue appears to have crossed two security limits at once: sandbox isolation and API authentication. OpenAI’s developer guide tells developers to create an API key before making requests, while its Responses API provides access to models and tools for agent workflows.

If Fish’s claim is correct, a remote user could have sent model requests through an internal route and avoided the normal identity and billing checks.

OpenAI Sandbox Escape Vulnerability

Technical details remain private. No proof-of-concept code, vulnerable endpoint, affected model list, CVE, exposure period, or patch note was available in the available material.

There is also no public proof that customer data was reached or that the flaw was exploited outside Fish’s testing. The finding should therefore be treated as a researcher claim, not a confirmed mass breach.

The $300 payment has drawn criticism. Fish wrote on X, “Zero reason to report anything else I find to them,” showing frustration with the reward. OpenAI says its Bugcrowd program pays from $200 for low-severity findings to $20,000 for exceptional bugs, based on severity and impact. The small award may mean OpenAI rated the real impact lower than the report title suggests, but the company has not explained that decision.

Sandbox security is a major concern around AI services. Cyber Security News previously covered a ChatGPT sandbox flaw that exposed Gmail data and OpenAI agents bypassing sandbox limits. Those cases show why shared internal services, weak access rules, and allowed network paths must be tested as security boundaries.

OpenAI should confirm the affected service, fix date, exposure window, and whether logs show unapproved use. API providers should enforce authentication at every internal hop, block anonymous model calls, add strict rate and spending limits, and alert on requests without a valid customer identity. Users should monitor API bills and logs, though key rotation won’t address a server-side authentication bypass.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post OpenAI Sandbox Escape Flaw Allowed Free Access to Paid AI Models Without an API Key appeared first on Cyber Security News.