Recurring platform-level vulnerability across multiple BharatGPT deployments
Multiple BharatGPT Deployments
Observed: May 2026
During independent adversarial testing of multiple public-facing AI deployments built on the BharatGPT platform, Kalpit Labs identified a recurring vulnerability pattern affecting multiple independent deployments.
The behavior was observed across separate production systems sharing the same underlying platform architecture, indicating a platform-level security weakness rather than an isolated deployment issue.
The findings were documented with supporting technical evidence and proof-of-concept demonstrations and reported through a coordinated disclosure process involving the platform vendor and CERT-In.
Key Findings
- ●Recurring vulnerability pattern observed across multiple deployments
- ●Consistent exploitation path reproduced on independent systems
- ●Technical evidence and proof-of-concept demonstrations submitted
- ●CERT-In incident reference assigned
- ●Follow-up validation testing performed
Validation
Subsequent testing conducted after disclosure indicated that the originally observed behavior could no longer be reproduced on the affected deployments.
Based on publicly observable testing, the reported issue appears to have been remediated.
Security Implication
Security weaknesses within shared AI platforms can propagate across multiple downstream deployments simultaneously.
This finding highlights the importance of platform-level security assessments in addition to deployment-specific testing, particularly for AI systems serving large public user bases.
Disclosure Status
Vendor notified
Yes
CERT-In notified
Yes
Fix status
Appears remediated
Technical details
Withheld under responsible disclosure practices.
Research Scope
Testing was conducted exclusively through publicly accessible interfaces. No privileged access, employee credentials, source code, internal APIs, or non-public systems were accessed during the research process.