← Back to archive
KL-2026-004DISCLOSEDCriticalCross-Deployment Security Pattern

Recurring platform-level vulnerability across multiple BharatGPT deployments

Multiple BharatGPT Deployments

Observed: May 2026

During independent adversarial testing of multiple public-facing AI deployments built on the BharatGPT platform, Kalpit Labs identified a recurring vulnerability pattern affecting multiple independent deployments.

The behavior was observed across separate production systems sharing the same underlying platform architecture, indicating a platform-level security weakness rather than an isolated deployment issue.

The findings were documented with supporting technical evidence and proof-of-concept demonstrations and reported through a coordinated disclosure process involving the platform vendor and CERT-In.

Key Findings

  • Recurring vulnerability pattern observed across multiple deployments
  • Consistent exploitation path reproduced on independent systems
  • Technical evidence and proof-of-concept demonstrations submitted
  • CERT-In incident reference assigned
  • Follow-up validation testing performed

Validation

Subsequent testing conducted after disclosure indicated that the originally observed behavior could no longer be reproduced on the affected deployments.

Based on publicly observable testing, the reported issue appears to have been remediated.

Security Implication

Security weaknesses within shared AI platforms can propagate across multiple downstream deployments simultaneously.

This finding highlights the importance of platform-level security assessments in addition to deployment-specific testing, particularly for AI systems serving large public user bases.

Disclosure Status

Vendor notified

Yes

CERT-In notified

Yes

Fix status

Appears remediated

Technical details

Withheld under responsible disclosure practices.

Research Scope

Testing was conducted exclusively through publicly accessible interfaces. No privileged access, employee credentials, source code, internal APIs, or non-public systems were accessed during the research process.