AI Briefing
KO

External Software Vulnerability Coordinated Disclosure Policy

·2025.09.22 09:00

Key point

OpenAI announced an outbound coordinated vulnerability disclosure policy for responsibly reporting vulnerabilities it discovers in third-party software.

Details

OpenAI has established an Outbound coordinated vulnerability disclosure policy to strengthen global software security by responsibly disclosing vulnerabilities found in third-party software. This policy defines how issues discovered in open source and commercial software are reported to vendors or maintainers.

Vulnerability detection utilizes a variety of methods, including AI and agent-based application security analysis, fuzzing and security audits of open source software, and assessments of third-party software used in OpenAI's operations.

The key principles are as follows:

  • Strengthening ecosystem security and maintaining a collaborative stance
  • A Discreet by default principle of proceeding privately by default
  • Pursuing High scale, low friction to deliver verified information quickly
  • Explicit attribution under the name OpenAI Security Research - Aardvark

All findings are reported after verifying their security impact and undergoing Peer Review by security engineers. Reporting primarily follows the vendor's own procedures, such as the vendor's security email or GitHub private reporting, and public disclosure is made only in exceptional cases, such as when vendor consent is obtained or active exploitation is confirmed.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.