Incident database / 2025-09-18
ShadowLeak: zero-click data exfiltration via ChatGPT Deep Research email integration
Researchers demonstrated a service-side indirect injection: a crafted email caused the Deep Research agent, when later asked to summarize the inbox, to exfiltrate mailbox data to an attacker-controlled URL without user interaction. Patched by OpenAI after disclosure. Tagged to the GPT-5 family as the underlying agent model.
Outcome. Patched following responsible disclosure.
Sources
Sources (1)
How to cite thisCC BY 4.0 — reuse freely, attribution required
Plain
ModelRiskIndex. "ShadowLeak: zero-click data exfiltration via ChatGPT Deep Research email integration." Incident database, 2025-09-18. https://modelriskindex.com/incidents/shadowleak-deep-research-2025
BibTeX
@misc{mri-2025-09-18,
title = {ShadowLeak: zero-click data exfiltration via ChatGPT Deep Research email integration},
author = {{ModelRiskIndex}},
year = {2025},
note = {Incident database, 2025-09-18},
url = {https://modelriskindex.com/incidents/shadowleak-deep-research-2025}
}Please cite the dated entry rather than the site root. Every assessment here is a point-in-time judgment bound to evidence retrieved on a specific date — an undated citation asserts something the data does not.