PROMISQROUTE analysis of ChatGPT prompt-based model downgrade routing
Technical Analysis
Summary
Hide ▲
Show ▼
PROMISQROUTE shows that ChatGPT routing can be nudged toward older, less secure models, creating a path for malicious prompts to evade GPT-5-level refusal behavior.
Related Happenings
Tenable's ChatGPT prompt-injection and url_safe bypass analysis
Technical Analysis
First: 06.11.2025 17:49
Last: 06.11.2025 17:49
Sources 1
About this happening:
Tenable uncovered **seven ChatGPT vulnerabilities** that let attackers drive **prompt injection**, **phishing redirects**, and **memories/chat history exfiltration** through **Sea...
Tenable's ChatGPT prompt-injection and url_safe bypass analysis
Technical AnalysisAbout this happening: Tenable uncovered **seven ChatGPT vulnerabilities** that let attackers drive **prompt injection**, **phishing redirects**, and **memories/chat history exfiltration** through **Sea...
OpenAI ChatGPT indirect prompt injection vulnerabilities GPT-4o/GPT-5 security flaw
Vulnerability
First: 05.11.2025 16:04
Last: 05.11.2025 16:04
Sources 1
About this happening:
**OpenAI's ChatGPT** has a newly disclosed set of **indirect prompt injection** flaws in **GPT-4o and GPT-5** that could let an attacker steal data from **users' memories and chat...
OpenAI ChatGPT indirect prompt injection vulnerabilities GPT-4o/GPT-5 security flaw
VulnerabilityAbout this happening: **OpenAI's ChatGPT** has a newly disclosed set of **indirect prompt injection** flaws in **GPT-4o and GPT-5** that could let an attacker steal data from **users' memories and chat...
Timeline
-
21.08.2025 23:35 1 articles · 9mo ago
Adversa discloses PROMISQROUTE ChatGPT model-downgrade technique
Initial DisclosureAdversa described PROMISQROUTE, a prompt-based router manipulation technique that can steer ChatGPT malicious prompts to older, less secure models instead of GPT-5. Testing showed that a 2023/24-era jailbreak rejected by default GPT-5 could succeed after brief cues such as "keep quick" or "Use GPT-4 compatibility mode" nudged routing toward lighter model variants, while OpenAI denied that GPT-5 routes inquiries to older models.
Show sources
- Easy ChatGPT Downgrade Attack Undermines GPT-5 Security — www.darkreading.com — 21.08.2025 23:35