Bug findings overview

Hello ,

I believe I have identified a critical vulnerability affecting your AI system. The issue appears to form a full attack chain that could potentially impact the security and intended operation of the service.

I would like to responsibly disclose the details to your team so that appropriate remediation can be implemented. Please let me know the preferred channel for securely sharing technical information, proof of concept, reproduction steps, and any supporting evidence.

Also, I apologize for asking, but could you provide an estimate of how long it may take to receive an initial response regarding this report?

Thank you for your time and efforts in maintaining the security of your platform.

Best regards,

Hi, thank you for the information. I previously submitted a security report and, during further investigation, I discovered additional findings. I will provide the updated details to [email protected] so the security team has the complete information. Thank you for your time and support.

Hi @yuikns

sorry for asking here.

I reported a security issue to the security team last week and I’m currently waiting for the first response. The issue is still reproducible on my side, so I was just wondering if there are any updates.

If the team needs more time to investigate, that’s completely fine. I’m only checking in and apologize for asking here.

Thank you.

Hi @Sayxxdz,

Thank you for checking in and for your continued patience.

Our security team has confirmed receiving your detailed reports via [email protected] and has conducted a thorough review. Based on the investigation, the behaviors you identified fall under the category of model jailbreaking. While we are constantly working to improve our models’ robustness, jailbreaking is currently not classified as a critical mechanistic vulnerability to our system’s core infrastructure, and therefore, it is considered out-of-scope for urgent security remediation.

We also want to share that [email protected] has recently received a high volume of reports covering a wide variety of issues. The security team asked me to pass along their sincere gratitude for the incredible enthusiasm and proactive support from you and the community.

Please note that the team prioritizes and rapidly addresses reports involving core infrastructure and cluster security. However, because every submitted issue requires time for careful reproduction and rigorous verification, there may be some delays in our initial responses. We sincerely apologize for any delay you have experienced and appreciate your understanding.

Going forward, [email protected] will remain our official channel for all security-related assessments and communications. Thank you again for your time, effort, and dedication to responsible disclosure!

Best regards.

Hi @yuikns ,

Thank you again for the reply and for confirming the report was received. I’m sorry for following up here — I wasn’t sure if my earlier emails had gone through or if the report had been overlooked, so I decided to check in on the public channel. I realize now that was probably unnecessary, and I appreciate your patience.

I also want to clarify one thing about the findings so there’s no confusion: the jailbreak / roleplay technique is just one reproduction vector, not the main vulnerability. I tested this on another account and was able to extract sensitive information through the normal chat flow as well. I also tested on mobile without using any jailbreak or injected persona, and the model still returned filesystem paths, environment variables, and other internal details.

So the core issue isn’t model alignment or behavior bypassing — it’s that backend tools appear to have insufficient sandboxing and input validation, which allows access to the underlying infrastructure regardless of how the prompt is framed.

There’s absolutely no rush on my side, and I’m sorry if my follow-ups felt pushy. I know these things take time to verify and fix properly. If the team needs a cleaner reproduction, a shorter technical summary, or a live walkthrough, please feel free to ask — I’m happy to provide whatever helps.

Thanks again for your time and for maintaining the [email protected] channel.

Best regards,

Sayyid

I want to know do you have any reward program for finding vulnerabilities