/dev/posts/

Tool call execution through user prompt injection (CSRF) of the llama-server Web UI

Published:

A user prompt injection vulnerability (CSRF) in the llama-server (llama.cpp) Web UI (Reprompt-like) allows attackers to inject arbitrary user prompt with query parameter (?q=...), potentially leading to arbitrary shell command execution, data exfiltration, etc. (through tool calls).

Read more…

Page 1 of 1 | | | JSON Feed | Atom Feed | RSS Feed