Vulnerability Description
OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-11326?
CVE-2026-11326 is a documented vulnerability. OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functio...
How severe is CVE-2026-11326?
CVSS scoring is not yet available for CVE-2026-11326. Check NVD for updates.
Is there a patch for CVE-2026-11326?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.