← Back to feed
AI SecurityEmerging1 sourceJun 20, 2023 · 15:00via Embrace The Red (AI agent security)

Plugin Vulnerabilities: Visit a Website and Have Your Source Code Stolen

Brief

OpenAI continues to add plugins with security vulnerabilities to their store.

In particular powerful plugins that can impersonate a user are not getting the required security scrutiny, or a general mitigation at the platform level.

As a brief reminder, one of the challenges Large Language Model (LLM) User-Agents, like ChatGPT, and plugins face is the Confused Deputy Problem / Plugin Request Forgery Attacks , which means that during a Prompt Injection attack an adversary can issue commands to plugins to cause harm.

Read more on Embrace The Red (AI agent security)