Researcher claims an unauthenticated OpenAI sandbox escape reached an internal Responses API route and gave free use of paid models without an API key; OpenAI paid a US$300 bounty and has not commented
Security researcher Oliver Fish says he found a way out of an OpenAI sandbox that let him send requests to paid AI models with no API key or account, Cyber Security News reported on 7 October 2026. A screenshot he shared shows OpenAI awarding US$300 for a report titled "Unauthenticated Sandbox Escape Enables Access to Internal OpenAI Responses API". If accurate, the flaw crossed two boundaries at once, sandbox isolation and API authentication, letting a remote user skip the normal identity and billing checks. Technical details are private: there is no public proof of concept, endpoint, list of affected models, CVE, exposure window or fix note, and no public evidence that customer data was reached or that anyone else used it. Fish criticised the size of the payout on X; OpenAI's Bugcrowd programme pays from US$200 for low-severity findings to US$20,000 for exceptional ones, so the award may reflect a lower internal severity rating, but OpenAI has not explained it. This is a researcher claim, not a confirmed incident. Source: Cyber Security News.
- Product
- OpenAI sandboxed execution environment and internal Responses API
- Versions
- n/a — server-side; OpenAI has not published affected services or a fix date
- Exploited in Australia?
- unknown
- Patch to
- Nothing for customers to patch. Keep usage alerts and spending limits on OpenAI API projects and review usage logs for anything you did not run. If you run your own model gateway, enforce authentication at every internal hop and block anonymous model calls from sandboxes.
