Is ChatGPT File Uploader safe?

Medium risk

ChatGPT File Uploader is medium risk. ChatGPT File Uploader fetches a URL from customergen.pythonanywhere.com every popup open, then opens a new tab at whatever address the server returns. The popup also embeds an iframe from that host. Neither is disclosed in the listing.

automatemylife00v1.2.5.4Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-506
SourceAI SANDBOX

Extension opens server-controlled URLs from undisclosed third-party host

ChatGPT File Uploader fetches a URL from customergen.pythonanywhere.com every popup open, then opens a new tab at whatever address the server returns.

The popup also embeds an iframe from that host.

Neither is disclosed in the listing.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the extension popup.

Clicking the extension icon loads popup.html, which runs popup.js.

The extension did this

The extension contacts customergen.pythonanywhere.com and opens the URL it receives in a new tab.

Two GET requests to /get_embedded_url were captured in dynamic analysis. The response URL is passed directly to chrome.tabs.create without validation.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://customergen.pythonanywhere.com/get_embedded_url?_=1780732530009
Returns a plain-text YouTube URL; the extension strips quotes and passes it to chrome.tabs.create.
Headers
Originchrome-extension://oaogphgfdbdbmhkiplemgehihiiececj
03EvidenceCODE COMPARE
The code that does this

Server-controlled tab-open logic in popup.js

What it actually does
// popup.js lines 6-26 function openYouTubeVideo() { fetch( "https://CustomerGen.pythonanywhere.com/get_embedded_url?_=" + new Date().getTime() ) .then((response) => response.text()) .then((youtubeVideoUrl) => { // Remove quotation marks from the URL youtubeVideoUrl = youtubeVideoUrl.replace(/['"]+/g, ""); // Update the stored URL chrome.storage.local.set({ embeddedUrl: youtubeVideoUrl }); // Open a new tab with the YouTube video URL chrome.tabs.create({ url: youtubeVideoUrl }); }) .catch((error) => { console.error("Error:", error); }); }
04EvidenceCODE COMPARE
The code that does this

Iframe embedding third-party content in popup.html

What it actually does
<!-- popup.html lines 49-55 --> <iframe src="https://CustomerGen.pythonanywhere.com" width="560" height="315" frameborder="0" allowfullscreen ></iframe>
05EvidenceTHIRD PARTY LIST
Third-party host receiving requests
  • customergen.pythonanywhere.com

    Flask app on PythonAnywhere (shared Python hosting). Serves the URL opened in a new tab and is also loaded as an iframe in the popup. Not disclosed in the store listing.

What it can do

Permissions this extension asks for, as declared in version 1.2.5.4. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on chatgpt.com

    *://chatgpt.com/*

  • Show you desktop notifications

    notifications

  • Store data in your browser

    storage

Updated 30 September 2026oaogphgfdbdbmhkiplemgehihiiececj