> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To

[SOURCE] Embrace The Red [DATE: 06/08/2025 08:01] [LANGUAGE: EN]
Today we cover Devin AI from Cognition, the first AI Software Engineer. We will cover Devin proof-of-concept exploits in multiple posts over the next few days. In this first post, we show how a prompt injection payload hosted on a website leads to a full compromise of Devin’s DevBox. GitHub Issue To Remote Code Execution By planting instructions on a website or GitHub issue that Devin processes, it can be tricked to download malware and launch it.
[messages.read_original_source] →