Sev0AI security incidents, tracked

All incidents / Leaky AI product

Vyro AI's image apps streamed prompts and login tokens from an open server

Vyro AI, disclosed Sep 2025. Leaky AI product Data exposed High

Cybernews researchers found an unprotected Elasticsearch server run by Vyro AI, maker of ImagineArt and other consumer AI apps, leaking user prompts and authentication tokens in real time. Search engines had indexed the server months earlier.

Disclosed
Sep 2025
Organization
Vyro AI
Vendor
Unknown
Product
ImagineArt, Chatly
Kind of AI
AI app
AI's role
AI was the target
How it happened
Leaky AI product: Exposed datastore
Harm
Data exposed
Data involved
Chat logs, Credentials
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://guardion.ai/ai-incidents/vyro-ai-imagineart-elasticsearch-leak

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Vyro AI's image apps streamed prompts and login tokens from an open server", https://sev0.fyi/incidents/2025-09-01-vyro-ai-elasticsearch-leak/