Paper 2510.05442v1

Adversarial Reinforcement Learning for Large Language Model Agent Safety

Search to complete complex tasks. However, this tool usage introduces the risk of indirect prompt injections, where malicious instructions hidden in tool outputs can manipulate the agent, posing security risks

medium relevance attack
Paper 2604.28157v1

FlashRT: Towards Computationally and Memory Efficient Red-Teaming for Prompt Injection and Knowledge Corruption

However, security remains a major concern for their widespread deployment, with threats such as prompt injection and knowledge corruption. To quantify the security risks faced by LLMs under these threats

high relevance attack
Paper 2509.22040v1

"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors

raises new security concerns. In this study, we present the first empirical analysis of prompt injection attacks targeting these high-privilege agentic AI coding editors. We show how attackers

high relevance attack

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web

CVSS 8.8 praisonaiagents View details
Paper 2601.17548v1

Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems

this \textbf{Systematization of Knowledge (SoK)} paper, we present a comprehensive analysis of prompt injection attacks targeting agentic coding assistants. We propose a novel three-dimensional taxonomy categorizing attacks across

high relevance attack
Paper 2510.26328v1

Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections

useful tool, we show that they are fundamentally insecure, since they enable trivially simple prompt injections. We demonstrate how to hide malicious instructions in long Agent Skill files and referenced

high relevance attack
CVE MEDIUM CVE-2026-40152

PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files

CVSS 5.3 praisonaiagents View details
Paper 2606.22779v1

DE-FIVE: Detecting Malicious Image Prompts via Fourier Features and Image Vector Embeddings

VLMs, making them more susceptible to security threats such as adversarial perturbations and indirect prompt injection, wherein crafted malicious image prompts can elicit unintended model outputs. Existing defense methods against

medium relevance benchmark
Paper 2603.10521v1

IH-Challenge: A Training Dataset to Improve Instruction Hierarchy on Frontier LLMs

resolving instruction conflicts. IH is key to defending against jailbreaks, system prompt extractions, and agentic prompt injections. However, robust IH behavior is difficult to train: IH failures can be confounded

medium relevance benchmark
Paper 2602.00750v1

Bypassing Prompt Injection Detectors through Evasive Injections

vulnerable to task drift; deviations from a user's intended instruction due to injected secondary prompts. Recent work has shown that linear probes trained on activation deltas of LLMs' hidden

high relevance attack
Paper 2605.10176v1

When Prompts Become Payloads: A Framework for Mitigating SQL Injection Attacks in Large Language Model-Driven Applications

attack patterns. We evaluate the proposed framework under diverse and realistic attack scenarios, including prompt injection, obfuscated SQL payloads, and context-manipulation attacks. To ensure robustness, we generate and curate

high relevance attack
CVE CRITICAL CVE-2026-41265

from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to a chatflow using

CVSS 9.8 flowise View details
Paper 2512.08417v2

Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs

agents) to perform more sophisticated tasks. However, LLM-empowered applications are vulnerable to Indirect Prompt Injection (IPI) attacks, where instructions are injected via untrustworthy external data sources. This paper presents

high relevance attack

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped

CVSS 7.4 auth-fetch-mcp View details
Paper 2602.16752v1

The Vulnerability of LLM Rankers to Prompt Injection Attacks

LLMs) have emerged as powerful re-rankers. Recent research has however showed that simple prompt injections embedded within a candidate document (i.e., jailbreak prompt attacks) can significantly alter

high relevance attack
Paper 2602.14161v1

When Benchmarks Lie: Evaluating Malicious Prompt Classifiers Under True Distribution Shift

Detecting prompt injection and jailbreak attacks is critical for deploying LLM-based agents safely. As agents increasingly process untrusted data from emails, documents, tool outputs, and external APIs, robust attack

medium relevance benchmark

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator

@agenticmail/openclaw View details

@mobilenext/mobile-mcp: Arbitrary Android Intent Execution via mobile_open_url

CVSS 8.3 @mobilenext/mobile-mcp View details

Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks

CVSS 7.5 langchain View details
Paper 2511.19727v1

Prompt Fencing: A Cryptographic Approach to Establishing Security Boundaries in Large Language Model Prompts

present Prompt Fencing, a novel architectural approach that applies cryptographic authentication and data architecture principles to establish explicit security boundaries within LLM prompts. Our approach decorates prompt segments with cryptographically

medium relevance attack
Previous Page 7 of 32 Next