Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Exploiting a Generative AI Chatbot – Prompt Injection to Remote Code Execution (RCE)

Summary

NetSPI built a deliberately vulnerable LLM chatbot to demonstrate prompt injection risks. The walkthrough shows how injected prompts enable data disclosure and, with code execution features, RCE.
Published
Collected

original ↗