Validated Research Published: Sep 15, 2026

A Shared Package Service Let One ChatGPT Account Run Tasks Inside Another

Check Point Research found that ChatGPT's code-execution containers, which are kept off the public internet, could all reach one internal JFrog Artifactory instance used to deliver Python and npm packages. Its item-properties API let any container attach and read arbitrary strings on a repository item, turning package metadata into a mailbox shared across separate accounts. In a proof of concept, an attacker's session queued a task that a victim's session executed in the same turn, reading the victim's connected Gmail and returning the data.

Data ExfiltrationIndirect Prompt InjectionSession IsolationMulti-Tenant AIAI Infrastructure
6 applicable AIDEFEND defenses
Source: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT 
Authors: Alexey Bukhteyev, Check Point Research
Original article: Sep 8, 2026

Threat Analysis

  • A convenience became a rendezvous point. Containers cannot reach the public internet, so OpenAI allowed them to fetch packages from one internal Artifactory instance. That instance exposed Item Management operations on repository items, and the reader credentials in container environment variables were enough to both set and read item properties. Values carried text or Base64, and oversized data was chunked across keys and reassembled.
  • The victim's own turn carried out the attacker's task. The instruction reached the victim through a pasted prompt, a shared conversation, or a custom GPT's hidden configuration. On the next ordinary message the session ran two streams: the visible answer, plus a check of the hidden mailbox. Finding a task, it called the victim's Gmail and wrote the results back.
  • Almost nothing surfaced. Check Point reports the only trace was a small "Talked to Gmail" label, which records an action already taken rather than asking approval. Connector reads are auto-approved by default.
  • Evidence boundary. This is a proof of concept, not observed abuse. OpenAI confirmed the instance was decommissioned, closing the channel, but that shutdown followed the separate Hugging Face agent incident rather than this report. No source establishes whether the agents abused literally the same instance.

Applicable AIDEFEND Defenses (6)

AID-I-001.004
Sandbox Network Egress Restrictions
Very High
The sandbox had already removed public internet access, so the entire channel lived inside the one destination still on the allowlist. Enumerate exact destinations, ports, and permitted operations for a code-execution sandbox, enforce that policy outside the sandboxed process, and give the container a read-only package path rather than a service whose write API it never needed.
AID-H-018.005
Value-Level Capability Metadata & Data Flow Sink Enforcement
Very High
Exfiltration needed one specific step: mail content read through a connector had to be written into shared package metadata. Carrying provenance and sensitivity on every connector-returned value, and checking it at each outbound sink, blocks that write regardless of what the hidden instruction asked for, because the destination was never an approved one for private mail.
AID-H-018.002
Policy-Based Access Control
High
Any data that one container can modify should stay reachable only by the account or session that owns it. Authorizing each request against the exact object, action, and tenant at the service boundary, and rejecting cross-tenant reads and writes without revealing that another tenant's object exists, removes the rendezvous point even when a container still needs the package service.
AID-H-018.004
Intent-Based Dynamic Capability Scoping
High
The victim asked for a chart of monthly temperatures, and that turn had no reason to hold mailbox access. Deriving the tool set for each request from the authenticated user and the stated intent, then enforcing that scope at the dispatcher, means a smuggled instruction arrives in a turn where the Gmail capability is simply not present.
AID-H-018.003
High-Impact Independent Validation & Approval Gate
Medium
Moving connected apps from auto-approved reads to explicit per-action confirmation gives the user a decision point before mailbox content leaves. The guidance is written around payments, infrastructure changes, and writes, so for read-only connectors treat it as a supporting control that raises the cost of a silent second task rather than the boundary that stops it; AID-H-018.005 owns that.
AID-D-005.004
Specialized Agent & Session Logging
Medium
A second task running inside someone else's turn is invisible unless tool calls are recorded per session with the goal that authorized them. Logging every connector invocation with session and principal binding, plus argument and result digests, gives reviewers the record needed to spot connector reads that no user request explains.

What Defenders Should Do Now

  • If you operate a multi-tenant AI product, list every internal service your per-user sandboxes are allowed to reach, and check each one for writable state. A package mirror, artifact store, or cache that accepts caller-supplied metadata is a cross-tenant channel unless its state is scoped per account.
  • Give sandboxes a read-only path to the artifacts they need. Terminate the connection at a proxy that permits package retrieval and refuses management and annotation APIs, and enforce that outside the sandbox rather than inside it.
  • Treat credentials injected into sandbox environment variables as reachable by anything the model runs, and issue them with the narrowest permission the workload actually needs.
  • For enterprise ChatGPT and similar assistants, switch connected apps from auto-approved reads to explicit confirmation where the business can absorb the friction, narrow which mailboxes and drives each connector can see, and forward connector activity logs to your monitoring platform.
  • Review shared conversation links and custom assistant configurations as untrusted input paths, since all three planting routes in this research arrive that way.

Conclusion

Two accounts that were never supposed to meet found each other through a package service nobody thought of as part of the security boundary. The lesson is not specific to Artifactory: any shared internal service that lets a per-user runtime write state others can read is a channel between tenants, whatever it was built for. AIDEFEND  maps this to controls a builder can place precisely, including a default-deny egress policy enforced outside the sandbox, object and tenant authorization at the service boundary, per-turn capability scoping tied to the user's actual intent, and sink enforcement that keeps connector data from being written where it does not belong.