Sev0

AI security incidents, tracked

All incidents / Leaky AI product

Vyro AI's image apps streamed prompts and login tokens from an open server

Vyro AI, disclosed 11 Sep 2025. Leaky AI product Data exposed High

Cybernews researchers found an unprotected Elasticsearch server run by Vyro AI, maker of ImagineArt, Chatly and Chatbotx, leaking 116 GB of live user logs including prompts and login tokens. Search engines for internet-connected devices had indexed it since mid-February, so it may have been visible for months.

Disclosed
11 Sep 2025
Organization
Vyro AI
Vendor
Unknown
Product
ImagineArt, Chatly
Type of AI
AI-powered app
How it happened
Leaky AI product: Exposed datastore
Harm
Data exposed
Data involved
Chat logs, Credentials
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://cybernews.com/security/ai-chatbots-vyro-data-leak/
  2. https://www.darkreading.com/cyberattacks-data-breaches/vyro-ai-leak-cyber-hygiene
  3. https://www.malwarebytes.com/blog/news/2025/09/when-ai-chatbots-leak-and-how-it-happens

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Vyro AI's image apps streamed prompts and login tokens from an open server", https://sev0.fyi/incidents/2025-09-11-vyro-ai-elasticsearch-leak/