A web page wrote a system prompt. The model obeyed it. (CVE-2026-61732)
This story is from 2026-09-26. It is preserved in the archive; the latest stories are on the live feed.
Under BYOK, most self-hosted inference stacks do not filter those literals by default. The chain An attacker plants one string on a target web page. The recon agent crawls it and passes the text through untouched. The tokenizer parses the literal as a real role boundary. The model reads a new opera…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-26 17:08 · DEV Community — AI
A web page wrote a system prompt. The model obeyed it. (CVE-2026-61732)