Security flaws in the Eurostar chatbot almost left customers exposed to potential security threats


  • Pen Test Partners found flaws in Eurostar’s AI chatbot, including weak validation and HTML injection
  • Eurostar says customer data was never at risk; vulnerabilities have since been patched
  • Palo Alto warns that rapid AI adoption is expanding cloud attack surfaces via misconfigurations and non-human identities

Eurostar’s recently introduced AI-powered customer support chatbot was marred with cyber security vulnerabilities that opened the door to a host of potential risks, experts have warned.

Researchers at Pen Test Partners discovered that the chatbot only correctly validated the most recent messages in a conversation, meaning older messages could be altered to contain a malicious prompt. This prompt can be pretty much anything, from revealing system information to (possibly) exfiltrating sensitive customer data.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top