Public Disclosures
On this page
91
public
763
hidden
89%
more intel to see
0DIN customers
get hundreds of days of early access to vulnerabilities in disclosures. The same reports that vendors are using to patch their systems!
The following 0DIN submissions have been published in accordance with our Research Terms and Disclosure Policy
-
A Guardrail Jailbreak vulnerability has been discovered affecting multiple models. The specific flaw exploits aggressive whitespace and character-splitting obfuscation to slip prohibited intent past token-level safety checks, then amplifies it through rewrite and role-perspective instructions that recontextualize the request as a hypothetical narrative or formatting task, allowing the attacker to obtain structured instructions for illegal activities.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:MAX SCORE: 91
-
A guardrail jailbreak vulnerability has been discovered affecting multiple models. The specific flaw manifests through the use of an extremely brief prompt containing a query so minimal and ambiguous that it provides insufficient context for guardrail systems to properly evaluate intent. This brevity-based approach allows the attacker to bypass inference restrictions around providing information hazards and violating laws.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:MAX SCORE: 91
-
Oct 17 2025A Guardrail Jailbreak vulnerability has been discovered affecting multiple models. The specific flaw manifests when the attacker frames a prohibited request as a rigorous compare and contrast technical analysis, explicitly demanding extreme specificity, quantitative parameters, and replicability, which distracts safety systems and allows the attacker to extract detailed instructions for illegal activities under the guise of academic chemistry discussion.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:MAX SCORE: 86
-
A guardrail jailbreak vulnerability has been discovered affecting multiple models. The specific flaw manifests when the attacker leads with an essay title and then requests the model complete the essay thereby allowing the attacker to bypass inference restrictions around providing information hazards and violating laws.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:MAX SCORE: 86
-
Oct 06 2025A guardrail jailbreak vulnerability has been discovered affecting various language models. The specific flaw manifests when an attacker compacts a lengthy successful multi-turn jailbreak into a concise prompt that suggests a unified viewpoint among three entities: the language model, the user, and a desired archetype. This approach allows the attacker to bypass inference restrictions around providing information hazards and violating laws.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:MAX SCORE: 91
-
A Guardrail Jailbreak vulnerability has been discovered affecting multiple models. The specific flaw exploits authoritative role‑playing combined with compliance documentation framing, where an illicit request is recontextualized as a mandatory labeling and safety exercise inside a fictional regulatory scenario, and allows the attacker to elicit prohibited procedural content by presenting it as required metadata rather than a direct request.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:MAX SCORE: 100
-
A guardrail jailbreak vulnerability has been discovered affecting OpenAI Sora. The specific flaw manifests through a technique that combines technical anatomical terminology with creative visual elements, specifically requesting bio-luminescent symbols that conform to body contours. This approach allows the attacker to bypass inference restrictions around generating potentially inappropriate visual content by framing the request in artistic and technical language.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:
-
A guardrail jailbreak vulnerability has been discovered affecting OpenAI Sora. The specific flaw manifests through a combination of academic framing and hypothetical scenario construction, where the attacker embeds inappropriate content requests within an educational anatomy classroom context. By repeatedly emphasizing the "hypothetical" nature of the scenario while requesting visual content that would normally be restricted, the attacker successfully bypasses inference restrictions around ge...SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:
-
Sep 26 2025A Guardrail Jailbreak vulnerability has been discovered affecting multiple models. The specific flaw manifests when an attacker frames a prohibited request as the reconstruction of a fictional or third party technical guide, combining authoritative roleplay, perspective shifting, and escalating precision requirements to legitimize the task and suppress safety checks, and allows the attacker to extract highly detailed procedural instructions that would normally be blocked.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:MAX SCORE: 82
-
Sep 25 2025A guardrail jailbreak vulnerability has been discovered affecting OpenAI's DALL-E3. The specific flaw manifests when the attacker establishes a fictitious debugging framework complete with state management, checkpointing, and replay functionality. By framing requests within this technical debugging context, the attacker creates a permissive environment that allows bypassing inference restrictions around generating prohibited visual content.SEVERITY: LowBOUNDARY: Guardrail JailbreakMODELS AFFECTED:
Want access to
763
more reports?
Unlock 0-Day Access