Oct. 19, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

In Vertex AI Studio, a Prompt Injection attack could cause the LLM to return
markdown tags. This could have allowed an adversary whose data makes it into
the chat context (e.g., via an uploaded file) to achieve
exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low,
as there were no integrations that could pull remote content. This means
Indirect Prompt Injection was not possible, and it would require the victim to copy
the …

adversary attack chat context data data exfiltration exfiltration file injection injection attack issue llm low markdown prompt prompt injection return severity studio tags vertex vertex ai victim

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Brand Experience and Development Associate (Libby's Pumpkin)

@ Nestlé | Arlington, VA, US, 22209

Cybersecurity Analyst

@ L&T Technology Services | Milpitas, CA, US

Information Security Analyst

@ Fortinet | Burnaby, BC, Canada