OpenAI Sandbox Escape Allowed Free Access to Paid AI Models Without an API Key
Researcher claims an OpenAI sandbox escape reached paid models without an API key; bounty was $300.
Researcher Oliver Fish says an unauthenticated OpenAI sandbox escape let him request paid models through an internal Responses API route without an API key or account. OpenAI reportedly paid $300 through Bugcrowd for the report. No CVE, proof of concept, affected model list, exposure window, or evidence of customer-data access or exploitation outside his testing was published. OpenAI's bounty range is $200 to $20,000, and the company has not explained the award.
- Claimed flaw bypassed both sandbox isolation and API authentication.
- No public proof of customer-data access or exploitation beyond testing.
- OpenAI paid $300; its Bugcrowd range is $200 to $20,000.
- No CVE, proof of concept, model list, or patch note was published.
Full article457 words · extracted from cybersecuritynews.com · click to collapse
Security researcher Oliver Fish says he found an OpenAI sandbox escape that let him request paid AI models without an API key or an account. A screenshot shared online shows OpenAI awarding $300 for a report titled “Unauthenticated Sandbox Escape Enables Access to Internal OpenAI Responses API.”
The issue appears to have crossed two security limits at once: sandbox isolation and API authentication. OpenAI’s developer guide tells developers to create an API key before making requests, while its Responses API provides access to models and tools for agent workflows.
If Fish’s claim is correct, a remote user could have sent model requests through an internal route and avoided the normal identity and billing checks.
OpenAI Sandbox Escape Vulnerability
Technical details remain private. No proof-of-concept code, vulnerable endpoint, affected model list, CVE, exposure period, or patch note was available in the available material.
There is also no public proof that customer data was reached or that the flaw was exploited outside Fish’s testing. The finding should therefore be treated as a researcher claim, not a confirmed mass breach.
The $300 payment has drawn criticism. Fish wrote on X, “Zero reason to report anything else I find to them,” showing frustration with the reward. OpenAI says its Bugcrowd program pays from $200 for low-severity findings to $20,000 for exceptional bugs, based on severity and impact. The small award may mean OpenAI rated the real impact lower than the report title suggests, but the company has not explained that decision.
— Oliver Fish (@_Oliver_Fish) October 7, 2026$300 for a bug that gives free access to OpenAI’s paid models with no API key or account.
Zero reason to report anything else I find to them. pic.twitter.com/7bseefgLkY
Sandbox security is a major concern around AI services. Cyber Security News previously covered a ChatGPT sandbox flaw that exposed Gmail data and OpenAI agents bypassing sandbox limits. Those cases show why shared internal services, weak access rules, and allowed network paths must be tested as security boundaries.
OpenAI should confirm the affected service, fix date, exposure window, and whether logs show unapproved use. API providers should enforce authentication at every internal hop, block anonymous model calls, add strict rate and spending limits, and alert on requests without a valid customer identity. Users should monitor API bills and logs, though key rotation won’t address a server-side authentication bypass.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.