BreachFeed
← All incidents
companyOpenAI
suspectedlowVulnerabilityFirst reported Oct 7, 2026

OpenAI: researcher reports sandbox escape giving unauthenticated access to paid models

Security researcher Oliver Fish reported an OpenAI sandbox escape that allegedly allowed requests to paid AI models without an API key or account. A screenshot shared online shows OpenAI awarding $300 for a report titled "Unauthenticated Sandbox Escape Enables Access to Internal OpenAI Responses API." No official OpenAI statement or advisory is cited, and no exploitation in the wild is reported.

Members only

The full record: the timeline and 1 linked report

  • Every update as it happened, with the status at each step
  • Every report behind the record, newest first
  • Alerts the moment OpenAI — or anything else you track — is hit again

A free account is all it takes — no card, one minute.

OpenAI: researcher reports sandbox escape giving unauthenticated access to paid models · BreachFeed