ATLAS Landscape
AML.T0070

RAG Poisoning

Adversaries may inject malicious content into data indexed by a retrieval augmented generation (RAG) system to contaminate a future thread through RAG-based search results. This may be accomplished by placing manipulated documents in a location the RAG indexes (see [Gather RAG-Indexed Targets](/techniques/AML.T0064)). The content may be targeted such that it would always surface as a search result for a specific user query. The adversary's content may include false or misleading information. It may also include prompt injections with malicious instructions, or false RAG entries.

Severity CVE CVSS
CRITICAL CVE-2025-1793 9.8
CRITICAL CVE-2025-6853 9.8
HIGH CVE-2026-41277 8.8
HIGH CVE-2026-44554 8.1
HIGH CVE-2026-28788 7.1
MEDIUM CVE-2025-6211 6.5
MEDIUM CVE-2021-28796 6.1
MEDIUM CVE-2026-40112 5.4
LOW CVE-2026-25211 3.2
LOW CVE-2026-7846 2.6
UNKNOWN CVE-2025-21604
LOW CVE-2025-65858