Prompt Injection Isn't a Vulnerability
josephthacker.com | research | #ai-security | #bug-bounty | #appsec | #prompt-injection | #llm | #data-exfiltration | #csp | #content-security-policy | #threat-model
Summary
Joseph Thacker argues prompt injection is usually a delivery mechanism, not the root cause—the real bug is what apps let AI do with injected output, such as markdown-image data exfiltration.
- Published
- Collected
Skip to content