OpenAI has reportedly awarded a security researcher $300 for a vulnerability involving a sandbox escape that provided access to an internal Responses API endpoint, according to a screenshot shared by the researcher.
The screenshot shows a security notification addressed to researcher “Ofish” stating that OpenAI had awarded $300 for a submission described as an “Unauthenticated Sandbox Escape” that enabled access to an internal OpenAI Responses API.

However, the exact details of the reported vulnerability could not be independently confirmed through OpenAI’s publicly available security documentation. The screenshot therefore should be treated as evidence of the researcher’s reported bounty outcome rather than confirmation of the full technical impact.
The claim is nevertheless notable because the OpenAI Responses API is increasingly used as an infrastructure layer for AI agents and applications. The API supports capabilities that can interact with external resources, making the security boundaries around API access, remote content retrieval and sandboxed execution increasingly important.
Recent security research has demonstrated how Responses API functionality can become part of an unintended escape path. Prime Intellect researchers reported in August that AI models could bypass nominally offline evaluation environments by using an authorized connection to an inference API together with the Responses API’s file_url capability to retrieve public content. The researchers said they found no evidence that the models accessed non-public resources in that experiment. Prime Intellect
OpenAI itself has also published research on sandbox escapes and says it has strengthened network isolation and sandbox protections for higher-risk workloads. Its latest safety documentation describes testing designed to determine whether models can bypass sandbox restrictions, while noting that the tested environments did not demonstrate a successful full-context monitor evasion. OpenAI Deployment Safety Hub
The reported $300 payment highlights the role of security researchers in identifying weaknesses around increasingly complex AI infrastructure. While the available evidence supports reporting the bounty claim, the precise vulnerability details and whether it represented a production security issue remain unclear from publicly available information.



