ATLAS Landscape
AML.T0080

AI Agent Context Poisoning

Adversaries may attempt to manipulate the context used by an AI agent's large language model (LLM) to influence the responses it generates or actions it takes. This allows an adversary to persistently change the behavior of the target agent and further their goals. Context poisoning can be accomplished by prompting the an LLM to add instructions or preferences to memory (See [Memory](/techniques/AML.T0080.000)) or by simply prompting an LLM that uses prior messages in a thread as part of its context (See [Thread](/techniques/AML.T0080.001)).

Severity CVE CVSS
CRITICAL CVE-2026-2654 9.8
CRITICAL CVE-2026-25130 9.7
CRITICAL CVE-2025-67511 9.6
CRITICAL CVE-2026-28451 9.3
CRITICAL CVE-2025-68665 9.1
CRITICAL CVE-2026-39305 9.0
HIGH GHSA-cwj3-vqpp-pmxr 8.8
HIGH CVE-2025-66404 8.8
HIGH CVE-2025-56265 8.8
HIGH CVE-2026-44552 8.7
HIGH CVE-2025-68664 8.2
HIGH CVE-2026-27826 8.2
HIGH CVE-2025-30358 8.1
HIGH CVE-2026-27001 7.8
HIGH CVE-2026-28788 7.1
HIGH GHSA-6r77-hqx7-7vw8 7.1
MEDIUM CVE-2026-21894 6.5
MEDIUM CVE-2026-27578 5.4
MEDIUM CVE-2025-11844 5.4
MEDIUM GHSA-3c7f-5hgj-h279 5.4
MEDIUM CVE-2026-40112 5.4
MEDIUM CVE-2026-44564 5.4
MEDIUM CVE-2026-41358 5.4
LOW CVE-2026-24764 3.7
MEDIUM GHSA-w8g9-x8gx-crmm
MEDIUM GHSA-3fv3-6p2v-gxwj
MEDIUM GHSA-qqq7-4hxc-x63c
LOW GHSA-57r2-h2wj-g887
HIGH CVE-2026-40160
UNKNOWN CVE-2025-55012
MEDIUM GHSA-hxvm-xjvf-93f3
UNKNOWN CVE-2025-59532
HIGH CVE-2025-64439
HIGH CVE-2026-39861
UNKNOWN CVE-2026-42228
MEDIUM GHSA-4p4f-fc8q-84m3
HIGH GHSA-gfmx-pph7-g46x
HIGH GHSA-jf56-mccx-5f3f