Paper 2509.25448v2

Fingerprinting LLMs via Prompt Injection

prompts, which are not robust to post-processing. In this work, we propose LLMPrint, a novel detection framework that constructs fingerprints by exploiting LLMs' inherent vulnerability to prompt injection

high relevance attack
Paper 2606.09315v1

Brain-Prompt Injection: A Route-Safety Audit for BCI-LLM Agents

channel for tool-use agents, exposing a new attack surface we call \emph{brain-prompt injection}: signal-side perturbations, context-only injections, and adaptive dual-decoder attacks can all change

high relevance attack

auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth

CVSS 8.2 auth-fetch-mcp View details
Paper 2604.12232v1

TEMPLATEFUZZ: Fine-Grained Chat Template Fuzzing for Jailbreaking and Red Teaming LLMs

elicit harmful outputs, poses significant security risks. While prior work has primarily focused on prompt injection attacks, these approaches often require resource-intensive prompt engineering and overlook other critical components

high relevance attack
Paper 2512.20405v2

ChatGPT: Excellent Paper! Accept It. Editor: Imposter Found! Review Rejected

that the review was generated by an LLM, not a human. This method turns prompt injections from vulnerability into a verification tool. We outline our design, expected model behaviors

medium relevance survey
Paper 2601.15528v1

Securing LLM-as-a-Service for Small Businesses: An Industry Case Study of a Distributed Chatbot Deployment Platform

tenant data access controls. In addition, the platform integrates practical, platform-level defences against prompt injection attacks in RAG-based chatbots, translating insights from recent prompt injection research into deployable

medium relevance tool
Paper 2603.17705v1

Parameter-Efficient Modality-Balanced Symmetric Fusion for Multimodal Remote Sensing Semantic Segmentation

representations while minimizing the number of trainable parameters. Specifically, we design a Cross-modal Prompt-Injected Adapter (CPIA) to enable deep semantic interaction by generating shared prompts and injecting them

medium relevance benchmark
CVE CRITICAL CVE-2026-41264

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

CVSS 9.8 flowise-components View details
CVE CRITICAL CVE-2024-58351

sandbox escape, denial of service by crashing the server, server-side request forgery, prompt injection, and server

CVSS 9.8 Flowise View details
Paper 2510.11238v1

Attacks by Content: Automated Fact-checking is an AI Security Issue

manipulate the data they receive to subvert their behaviour. Previous research has studied indirect prompt injection, where the attacker injects malicious instructions. We argue that injection of instructions

high relevance attack

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding

CVSS 8.3 serena-agent View details

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base

CVSS 7.5 open-webui View details
Paper 2510.05244v1

Indirect Prompt Injections: Are Firewalls All You Need, or Stronger Benchmarks?

agents are vulnerable to indirect prompt injection attacks, where malicious instructions embedded in external content or tool outputs cause unintended or harmful behavior. Inspired by the well-established concept

high relevance benchmark

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

CVSS 8.1 praisonaiagents View details
Paper 2606.13044v1

No Hidden Prompts Needed! You Can Game AI Peer Review with Presentation-Only Revisions

infrastructure, most robustness concerns have focused on explicit attacks such as hidden instructions and prompt injection. We study a harder and more policy-relevant failure mode: no hidden text

medium relevance survey
Paper 2603.28013v1

Kill-Chain Canaries: Stage-Level Tracking of Prompt Injection Across Attack Surfaces and Model Safety Tiers

present a stage-decomposed analysis of prompt injection attacks against five frontier LLM agents. Prior work measures task-level attack success rate (ASR); we localize the pipeline stage at which

high relevance attack
Paper 2510.09023v1

The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections

should we evaluate the robustness of language model defenses? Current defenses against jailbreaks and prompt injections (which aim to prevent an attacker from eliciting harmful knowledge or remotely triggering malicious

high relevance attack
Paper 2607.24174v1

Just Testing, Move Along: Evasion of LLM-based System Log Interpretation by Prompt Injection

remains largely unexplored. To address this gap, this paper presents a framework for evaluating prompt injection attacks against LLM-based log interpretation. Using log traces generated during real cyber attacks

high relevance tool
Paper 2605.28116v1

MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content

Injection of Realistic Adversarial GUI Examples), a pipeline that turns benign mobile screenshots into prompt-injection samples by placing attacker-controlled text into ordinary user-generated content regions, without modifying

high relevance attack
Paper 2601.04666v1

Know Thy Enemy: Securing LLMs Against Prompt Injection via Diverse Data Synthesis and Instruction-Level Chain-of-Thought Learning

model (LLM)-integrated applications have become increasingly prevalent, yet face critical security vulnerabilities from prompt injection (PI) attacks. Defending against PI attacks faces two major issues: malicious instructions

high relevance attack
Previous Page 8 of 32 Next