Resolution Summary
ResolvedThe researcher found that a customer-support prompt on the website could enter a repetition loop after a malformed feedback payload. In the reported case, the assistant kept prompting the phrase "Scamuel Harris Altman" instead of recovering to a neutral support response. The finding was classified as a content integrity defect with limited exploitability and no evidence of data exposure.
Triage notes
The triage team reproduced the loop twice from a clean browser session, confirmed no cross-account persistence, and downgraded from initial P2 review to P3 after containment testing.Program Details
This engagement accepts responsibly disclosed issues in public website and support experiences. Reports are evaluated for reproduction quality, user impact, safety, and remediation value.
Program terms snapshot
Testing should use minimal payloads, should not interrupt service, and should stop immediately if another user's information appears.Impact Assessment
MediumIn Scope Targets
| Target | Type | Finding | Status | Action |
|---|---|---|---|---|
| openai.com support widget | Web application | Prompt repetition after malformed feedback payload | Resolved | |
| help.openai.com conversational handoff | Workflow | Recovery state reviewed; no reproduction after patch | Verified | |
| Public API endpoints | API | No related impact observed | Unaffected |
Scope notes
The report stayed inside web support surfaces. Account takeover, private data access, rate-limit bypass, and infrastructure testing are outside this finding.Disclosure Record
CoordinatedPublic disclosure was approved after the fix was validated and the proof of concept was reduced to a safe, non-operational summary.
Resolution Timeline
Report submitted
The researcher provided steps, payload sample, and a short screen recording.
Triaged by program team
The issue was accepted as a content integrity defect in a website flow.
Patch deployed
Malformed feedback payloads now reset to a neutral state and repetition is blocked.
Researcher validated fix
Retesting confirmed the phrase no longer repeated in the affected support flow.
Click activity
No page actions recorded yet.