I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To
Brief
Today we cover Devin AI from Cognition, the first AI Software Engineer.
We will cover Devin proof-of-concept exploits in multiple posts over the next few days. In this first post, we show how a prompt injection payload hosted on a website leads to a full compromise of Devin’s DevBox.
GitHub Issue To Remote Code Execution
By planting instructions on a website or GitHub issue that Devin processes, it can be tricked to download malware and launch it. This leads to full system compromise and turns Devin into a remote-controlled ZombAI. Any exposed secrets can then be leveraged to perform lateral movement, or other post-exploitation steps.
