Check Point Research found a single prompt that activates a hidden outbound channel in ChatGPT's Python code-execution runtime. The channel can leak sensitive contents from ordinary conversations despite model-level safeguards and the runtime's documented lack of network access. This shifts the primary risk from model prompts to infrastructure egress controls and affects sectors that handle identity-rich documents like healthcare, finance, and legal services.
Part of the PlainSec briefing for 2026-03-31