> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Plugin Vulnerabilities: Visit a Website and Have Your Source Code Stolen

[SOURCE] Embrace The Red [DATE: 20/06/2023 15:00] [LANGUAGE: EN]
OpenAI continues to add plugins with security vulnerabilities to their store. In particular powerful plugins that can impersonate a user are not getting the required security scrutiny, or a general mitigation at the platform level. As a brief reminder, one of the challenges Large Language Model (LLM) User-Agents, like ChatGPT, and plugins face is the Confused Deputy Problem / Plugin Request Forgery Attacks, which means that during a Prompt Injection attack an adversary can issue commands to plugins to cause harm.
[messages.read_original_source] →