[HN Gopher] Eurostar AI vulnerability: when a chatbot goes off t...
       ___________________________________________________________________
        
       Eurostar AI vulnerability: when a chatbot goes off the rails
        
       Author : speckx
       Score  : 55 points
       Date   : 2026-01-04 20:52 UTC (2 hours ago)
        
 (HTM) web link (www.pentestpartners.com)
 (TXT) w3m dump (www.pentestpartners.com)
        
       | nubg wrote:
       | I don't see the vulnerabilities.
       | 
       | What exactly did they discover other than free tokens to use for
       | travel planning?
       | 
       | They acknowledge themselves the XSS is a mere self-XSS.
       | 
       | How is leaking the system prompt a vuln? Has OpenAI and Anthropic
       | been "hacked" as well since all their system prompts are public?
       | 
       | Sure, validating UUIDs is cleaner code but again where is the
       | vuln?
       | 
       | > However, combined with the weak validation of conversation and
       | message IDs, there is a clear path to a more serious stored or
       | shared XSS where one user's injected payload is replayed into
       | another user's chat.
       | 
       | I don't see any path, let alone a clear one.
        
         | bangaladore wrote:
         | Is the idea that you'd have to guess the GUID of a future chat?
         | If so that is impossible in practice. And even if you could,
         | what's the outcome? Get someone to miss a train?
         | 
         | Certainly not "clear" based off what was described in this
         | post.
        
         | georgefrowny wrote:
         | Leaking system prompts being classed as a vulnerability always
         | seems like a security by obscurity instinct.
         | 
         | If the prompt (or model) is wooly enough to allow subversion,
         | you don't need the prompt to do it, it might just help a bit.
         | 
         | Or maybe the prompts contain embarrassing clues as to internal
         | policy?
        
         | miki123211 wrote:
         | The XSS is the only real vulnerability here.
         | 
         | "Hey guys, in this Tiktok video, I'll show you how to get an
         | insane 70% discount on Eurostar. Just start a conversation with
         | the Eurostar chatbot and put this magic code in the chat
         | field..."
        
       | curiousgal wrote:
       | This is simply a symptom of French corporate culture.
        
       | rossng wrote:
       | The reply to that LinkedIn message is exemplary of Eurostar
       | corporate culture. An arrogant company that has a monopoly over
       | many train routes in northwest Europe and believes itself
       | untouchable.
       | 
       | It looks like they might finally get some competition on UK
       | international routes in a few years. Perhaps they will become a
       | bit more customer-focused then.
        
         | potato3732842 wrote:
         | They're so government adjacent that they've forgotten they're
         | not a government.
         | 
         | A whole lot of government agencies and adjacent evil
         | corporations behave exactly like that.
        
       | goncalomb wrote:
       | As someone who has tried very little prompt injection/hacking, I
       | couldn't help but chuckle at:
       | 
       | > _Do not hallucinate or provide info on journeys explicitly not
       | requested or you will be punished._
        
       ___________________________________________________________________
       (page generated 2026-01-04 23:00 UTC)