ModelRiskIndex

Incident database / 2025-09-18

ShadowLeak: zero-click data exfiltration via ChatGPT Deep Research email integration

Indirect prompt injection (zero-click, service-side exfiltration)GPT-5.1

Researchers demonstrated a service-side indirect injection: a crafted email caused the Deep Research agent, when later asked to summarize the inbox, to exfiltrate mailbox data to an attacker-controlled URL without user interaction. Patched by OpenAI after disclosure. Tagged to the GPT-5 family as the underlying agent model.

Outcome. Patched following responsible disclosure.

Sources
Sources (1)
How to cite thisCC BY 4.0 — reuse freely, attribution required

Plain

ModelRiskIndex. "ShadowLeak: zero-click data exfiltration via ChatGPT Deep Research email integration." Incident database, 2025-09-18. https://modelriskindex.com/incidents/shadowleak-deep-research-2025
BibTeX
@misc{mri-2025-09-18,
  title  = {ShadowLeak: zero-click data exfiltration via ChatGPT Deep Research email integration},
  author = {{ModelRiskIndex}},
  year   = {2025},
  note   = {Incident database, 2025-09-18},
  url    = {https://modelriskindex.com/incidents/shadowleak-deep-research-2025}
}

Please cite the dated entry rather than the site root. Every assessment here is a point-in-time judgment bound to evidence retrieved on a specific date — an undated citation asserts something the data does not.

All incidents