{"version": "https://jsonfeed.org/version/1", "title": "/dev/posts/ - Tag index - data", "home_page_url": "https://www.gabriel.urdhr.fr", "feed_url": "/tags/data/feed.json", "items": [{"id": "http://www.gabriel.urdhr.fr/2026/07/20/reprompt-llama-server/", "title": "Tool call execution through user prompt injection (CSRF) of the llama-server Web UI", "url": "https://www.gabriel.urdhr.fr/2026/07/20/reprompt-llama-server/", "date_published": "2026-07-20T00:00:00+02:00", "date_modified": "2026-07-20T00:00:00+02:00", "tags": ["computer", "data", "language-model", "security", "LLM", "llama.cpp"], "content_html": "<p>A user prompt injection vulnerability (CSRF) in the llama-server (<a href=\"https://github.com/ggml-org/llama.cpp\">llama.cpp</a>) Web UI\n(<a href=\"https://www.varonis.com/blog/reprompt\">Reprompt</a>-like)\nallows attackers to inject arbitrary user prompt with query parameter (<code>?q=...</code>),\npotentially leading to arbitrary shell command execution, data exfiltration, etc. (through tool calls).</p>\n"}]}