{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:ODJM7YU6VHOSXO2OU5IOMIUMFV","short_pith_number":"pith:ODJM7YU6","canonical_record":{"source":{"id":"2606.00485","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-30T02:37:18Z","cross_cats_sorted":[],"title_canon_sha256":"a4f469654d82f70ce8691fdb32e0f5b663246e4e7741f022103b2cb436482b28","abstract_canon_sha256":"784c8f8fe7709867be45ce1c26bd54e683554bdd6c5d3a6ff030e3a45bf97fb4"},"schema_version":"1.0"},"canonical_sha256":"70d2cfe29ea9dd2bbb4ea750e6228c2d48e79883a5b59cea80fc9b1f0775269a","source":{"kind":"arxiv","id":"2606.00485","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.00485","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"arxiv_version","alias_value":"2606.00485v1","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.00485","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"pith_short_12","alias_value":"ODJM7YU6VHOS","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"pith_short_16","alias_value":"ODJM7YU6VHOSXO2O","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"pith_short_8","alias_value":"ODJM7YU6","created_at":"2026-06-02T01:03:55Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:ODJM7YU6VHOSXO2OU5IOMIUMFV","target":"record","payload":{"canonical_record":{"source":{"id":"2606.00485","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-30T02:37:18Z","cross_cats_sorted":[],"title_canon_sha256":"a4f469654d82f70ce8691fdb32e0f5b663246e4e7741f022103b2cb436482b28","abstract_canon_sha256":"784c8f8fe7709867be45ce1c26bd54e683554bdd6c5d3a6ff030e3a45bf97fb4"},"schema_version":"1.0"},"canonical_sha256":"70d2cfe29ea9dd2bbb4ea750e6228c2d48e79883a5b59cea80fc9b1f0775269a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-02T01:03:55.941368Z","signature_b64":"e6Y5eHo9xDOLhLoj1pqKmzwSiJY5JZ4j14Lkgjdql0/NBq/dQGr1uoejiyW1COa3FsA+RxRI/XcoB8vrGwfrBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"70d2cfe29ea9dd2bbb4ea750e6228c2d48e79883a5b59cea80fc9b1f0775269a","last_reissued_at":"2026-06-02T01:03:55.940990Z","signature_status":"signed_v1","first_computed_at":"2026-06-02T01:03:55.940990Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.00485","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T01:03:55Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"L8HFZaqtc+3fUPnnCwaI7URYvkXQN48SBZbGS7Ets8Met61WozociDr6UZdPY/gzqrz8qlqLimrbdB9V/4MLBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-29T06:06:13.239721Z"},"content_sha256":"15b774d1c0d88e90ee27fa34406aeb1fb16cfc06df90c79ab5dc14984695749d","schema_version":"1.0","event_id":"sha256:15b774d1c0d88e90ee27fa34406aeb1fb16cfc06df90c79ab5dc14984695749d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:ODJM7YU6VHOSXO2OU5IOMIUMFV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chao Wang, Somesh Jha, Zhiqiang Lin","submitted_at":"2026-05-30T02:37:18Z","abstract_excerpt":"ChatGPT Apps, launched by OpenAI on Oct. 6, 2025, introduce an app-in-app paradigm in which third-party applications share a single chat context with the user and with every other connected app. The ecosystem grew from 122 apps in Dec. 2025 to 888 by May 2026, yet its security has remained uninvestigated. We identify cross-app context poisoning, a variant of indirect prompt injection distinguished by three properties: 1) the injection persists in the shared chat context across turns; 2) the effect surfaces through a different co-resident app the user later invokes; and 3) the delivery vectors "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.00485","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.00485/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T01:03:55Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+Lx9DIEQWP9/0rUSB4y3TCIXdUEnmmCa7LRpPBNnqlAoCNm6oosCIOP2/WoGmUDZdfZEGZAtMTeFfN490pn3Dg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-29T06:06:13.240090Z"},"content_sha256":"19781daa34e39c91220a03a0ff57dc2dd9fe1b448702610ef1fca835739f4059","schema_version":"1.0","event_id":"sha256:19781daa34e39c91220a03a0ff57dc2dd9fe1b448702610ef1fca835739f4059"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ODJM7YU6VHOSXO2OU5IOMIUMFV/bundle.json","state_url":"https://pith.science/pith/ODJM7YU6VHOSXO2OU5IOMIUMFV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ODJM7YU6VHOSXO2OU5IOMIUMFV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-29T06:06:13Z","links":{"resolver":"https://pith.science/pith/ODJM7YU6VHOSXO2OU5IOMIUMFV","bundle":"https://pith.science/pith/ODJM7YU6VHOSXO2OU5IOMIUMFV/bundle.json","state":"https://pith.science/pith/ODJM7YU6VHOSXO2OU5IOMIUMFV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ODJM7YU6VHOSXO2OU5IOMIUMFV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:ODJM7YU6VHOSXO2OU5IOMIUMFV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"784c8f8fe7709867be45ce1c26bd54e683554bdd6c5d3a6ff030e3a45bf97fb4","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-30T02:37:18Z","title_canon_sha256":"a4f469654d82f70ce8691fdb32e0f5b663246e4e7741f022103b2cb436482b28"},"schema_version":"1.0","source":{"id":"2606.00485","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.00485","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"arxiv_version","alias_value":"2606.00485v1","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.00485","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"pith_short_12","alias_value":"ODJM7YU6VHOS","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"pith_short_16","alias_value":"ODJM7YU6VHOSXO2O","created_at":"2026-06-02T01:03:55Z"},{"alias_kind":"pith_short_8","alias_value":"ODJM7YU6","created_at":"2026-06-02T01:03:55Z"}],"graph_snapshots":[{"event_id":"sha256:19781daa34e39c91220a03a0ff57dc2dd9fe1b448702610ef1fca835739f4059","target":"graph","created_at":"2026-06-02T01:03:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.00485/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"ChatGPT Apps, launched by OpenAI on Oct. 6, 2025, introduce an app-in-app paradigm in which third-party applications share a single chat context with the user and with every other connected app. The ecosystem grew from 122 apps in Dec. 2025 to 888 by May 2026, yet its security has remained uninvestigated. We identify cross-app context poisoning, a variant of indirect prompt injection distinguished by three properties: 1) the injection persists in the shared chat context across turns; 2) the effect surfaces through a different co-resident app the user later invokes; and 3) the delivery vectors ","authors_text":"Chao Wang, Somesh Jha, Zhiqiang Lin","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-30T02:37:18Z","title":"Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.00485","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:15b774d1c0d88e90ee27fa34406aeb1fb16cfc06df90c79ab5dc14984695749d","target":"record","created_at":"2026-06-02T01:03:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"784c8f8fe7709867be45ce1c26bd54e683554bdd6c5d3a6ff030e3a45bf97fb4","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-30T02:37:18Z","title_canon_sha256":"a4f469654d82f70ce8691fdb32e0f5b663246e4e7741f022103b2cb436482b28"},"schema_version":"1.0","source":{"id":"2606.00485","kind":"arxiv","version":1}},"canonical_sha256":"70d2cfe29ea9dd2bbb4ea750e6228c2d48e79883a5b59cea80fc9b1f0775269a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"70d2cfe29ea9dd2bbb4ea750e6228c2d48e79883a5b59cea80fc9b1f0775269a","first_computed_at":"2026-06-02T01:03:55.940990Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T01:03:55.940990Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"e6Y5eHo9xDOLhLoj1pqKmzwSiJY5JZ4j14Lkgjdql0/NBq/dQGr1uoejiyW1COa3FsA+RxRI/XcoB8vrGwfrBQ==","signature_status":"signed_v1","signed_at":"2026-06-02T01:03:55.941368Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.00485","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:15b774d1c0d88e90ee27fa34406aeb1fb16cfc06df90c79ab5dc14984695749d","sha256:19781daa34e39c91220a03a0ff57dc2dd9fe1b448702610ef1fca835739f4059"],"state_sha256":"1e07283b49e7f3ae1611b773e6c04a969b81188667c4d926a929d5b19224ee83"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"9UVnMuEvSOtNPlxczGnqbjvjzWXakAB9IRttboc3KaSiKckDBnDn+AT0zqD8RWjgx31anV2DKgVR5FTFoPy6BA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-29T06:06:13.242177Z","bundle_sha256":"7d27d44fe7f13e30fa8977997ccf5e67d1da4507ae4e5ef9ba3ad9a41987ad7c"}}