Threat · curated 10 Sep 2026

From IDOR to AI Manipulation: How I Poisoned Another User’s Persistent Chat Context

Coverage timeline

30 Aug 2026medium.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

The chain shows how a classic authorization flaw becomes persistent AI-context poisoning, letting an attacker silently manipulate another user's AI assistant with nothing more than a free account.

A bug bounty researcher (Manoj) found that an AI trip-planning assistant on a major travel platform trusts a client-supplied chatId without verifying ownership, letting any authenticated user read and write into another user's private AI conversation. Because injected messages are stored in the victim's chat history and fed back to the assistant as context, the IDOR/BOLA flaw escalates into persistent, no-interaction indirect prompt injection and AI-context poisoning that shapes the victim's future recommendations.