From prompt to pwned: chaining LLM and web bugs to Admin
blog.quarkslab.com | research | #ai-security | #web-security | #red-team | #llm | #pentest | #insecure-output-handling
Summary
A Quarkslab red-team case study: insecure output handling in an LLM medical assistant let them chain bugs from a low-privileged account to admin takeover — trusting the model was the first domino.
- Published
- Collected
Skip to content