OpenAI's vulnerability disclosures center on its conversational AI products, notably ChatGPT and Operator, where the durable signal reflects input-handling and security-control weaknesses including command injection and UI misrepresentation of critical information. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by OpenAI over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-7021MEDIUM Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input | Jul 10, 2025 | 6.5 | 17 | NO | NO |
CVE-2025-43714MEDIUM The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection | May 19, 2025 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by OpenAI.
Media articles that mention a CVE ID that affects a product developed by OpenAI — matched by CVE ID, not by vendor name.