Threat · curated 10 Sep 2026
From IDOR to AI Manipulation: How I Poisoned Another User’s Persistent Chat Context
First reported medium.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
The chain shows how a classic authorization flaw becomes persistent AI-context poisoning, letting an attacker silently manipulate another user's AI assistant with nothing more than a free account.
A bug bounty researcher (Manoj) found that an AI trip-planning assistant on a major travel platform trusts a client-supplied chatId without verifying ownership, letting any authenticated user read and write into another user's private AI conversation. Because injected messages are stored in the victim's chat history and fed back to the assistant as context, the IDOR/BOLA flaw escalates into persistent, no-interaction indirect prompt injection and AI-context poisoning that shapes the victim's future recommendations.