Description
OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later.
Published: 2026-06-05
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Before the 1.2025.288.15 release, OpenAI Atlas exposed privileged browser APIs to content served from *.openai.com origins. A cross‑site scripting flaw in forum.openai.com allows an attacker to inject scripts that can read the victim’s browser history and open or close tabs, effectively revealing sensitive browsing data and enabling unauthorized browser manipulation. The vulnerability represents an access‑control weakness (CWE‑284).

Affected Systems

All installations of OpenAI Atlas running a version older than 1.2025.288.15 are affected. The flaw is triggered by content on *.openai.com, particularly forum.openai.com. After the 1.2025.288.15 update, the exposure is limited to *.chatgpt.com only, meaning earlier versions remain vulnerable until upgraded.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 6 indicates moderate severity combined with a stored XSS vector and privileged API access, implying a moderate exploitation risk. Based on the description, it is inferred that the likely attack vector is a malicious script injected into a forum post that then runs in the context of the victim’s browser, granting the attacker read‑only access to browsing history and the ability to open or close tabs. Immediate remediation is advised to mitigate the potential for data leakage and session hijacking.

Generated by OpenCVE AI on June 5, 2026 at 20:41 UTC.

Remediation

Vendor Solution

Upgrade to OpenAI Atlas 1.2025.288.15 or later.


OpenCVE Recommended Actions

  • Upgrade to OpenAI Atlas 1.2025.288.15 or later
  • Configure a content security policy on forum.openai.com to disallow inline scripts and limit script sources, reducing the risk of XSS exploitation
  • Implement monitoring of browser history access and tab manipulation events, and review logs for suspicious activity to detect potential exploitation

Generated by OpenCVE AI on June 5, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 07 Jun 2026 01:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Allowing Browser History Access and Tab Control in OpenAI Atlas

Fri, 05 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/V:D/RE:L/U:Green'}


Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Openai
Openai openai Atlas
Vendors & Products Openai
Openai openai Atlas

Fri, 05 Jun 2026 05:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Allowing Browser History Access and Tab Control in OpenAI Atlas

Fri, 05 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Description OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later.
Weaknesses CWE-284
References

Subscriptions

Openai Openai Atlas
cve-icon MITRE

Status: PUBLISHED

Assigner: OAI

Published:

Updated: 2026-06-05T18:32:50.603Z

Reserved: 2026-06-05T00:07:13.696Z

Link: CVE-2026-11326

cve-icon Vulnrichment

Updated: 2026-06-05T18:32:46.951Z

cve-icon NVD

Status : Deferred

Published: 2026-06-05T02:17:11.180

Modified: 2026-06-05T18:17:04.343

Link: CVE-2026-11326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T20:45:04Z

Weaknesses