CVE-2024-27564PoC(dirk1983 / chatgpt)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for dirk1983 chatgpt systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chatgpt

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
chatgpt

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-11: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-02-11: 1Exploit Tool / Code · 2026-02-11: 1Technical Details · 2026-02-11: 1Technical Details · 2026-04-19: 102-1104-19
Signal classification2 categories
PoC
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-111
PoC1
2026-04-191
Disclosure1
Full discourse2 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2024-27564: OpenAI ChatGPT Server-Side Request Forgery PoC: https://github.com/chsxthwik/CVE-2024-27564 Vulnerable Parameter : pictureproxy.php?url=payload A vulnerability in pictureproxy.php allows remote attackers to perform arbitrary requests by injecting URLs into the url parameter. This SSRF vulnerability can be exploited without authentication.

    Post summary

    The post announces CVE‑2024‑27564, details an SSRF flaw in OpenAI ChatGPT's pictureproxy.php, and provides a link to a proof‑of‑concept repository.

    221093689.3K
    164.8K followersView on X
  • Crackshash_mod@Crackshash_mod
    Disclosure

    CRITICAL SSRF VULNERABILITY DISCOVERED — CVE-2024-27564 🚨 https://youtu.be/YLwg88Ldafw

    Post summary

    A video link announces the discovery of CVE-2024-27564, a critical SSRF vulnerability, but offers no further exploitation, mitigation, or detailed technical info.

    0000042
    22 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdirk1983chatgpt2023-05-23--

Explore more