ChatGPT Plugin Exploit Explained: From Prompt Injection to Accessing Private Data Embrace The Red 3 years ago If you are building ChatGPT plugins, LLM agents, tools or integrations this is a must read. This post explains how the first exploitable Cross Plugin Request Forgery was found in the wild and the fix which was applied. Indirect Prompt Injections Are Now A Reality With plugins and browsing support Indirect Prompt Injections are now a reality in the ChatGPT ecosystem. The real-world examples and demos provided by others and myself to raise awarness about this increasing problem have been mostly amusing and harmless, like making Bing Chat speak like a pirate, make ChatGPT add jokes at the end or having it do a Rickroll when reading YouTube transcripts.