<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>prompt-injection on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/categories/prompt-injection/</link><description>Recent content in prompt-injection on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Oct 2025 00:00:00 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/categories/prompt-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>Prompt injection to RCE in AI agents</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/10/22/prompt-injection-to-rce-in-ai-agents/</link><pubDate>Wed, 22 Oct 2025 07:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/10/22/prompt-injection-to-rce-in-ai-agents/</guid><description>We bypassed human approval protections for system command execution in AI agents, achieving RCE in three agent platforms.</description></item><item><title>Weaponizing image scaling against production AI systems</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/</link><pubDate>Thu, 21 Aug 2025 07:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/</guid><description>In this blog post, we’ll detail how attackers can exploit image scaling on Gemini CLI, Vertex AI Studio, Gemini’s web and API interfaces, Google Assistant, Genspark, and other production AI systems. We’ll also explain how to mitigate and defend against these attacks, and we’ll introduce Anamorpher, our open-source tool that lets you explore and generate these crafted images.</description></item><item><title>Deceiving users with ANSI terminal codes in MCP</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/04/29/deceiving-users-with-ansi-terminal-codes-in-mcp/</link><pubDate>Tue, 29 Apr 2025 09:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/04/29/deceiving-users-with-ansi-terminal-codes-in-mcp/</guid><description>This post describes attacks using ANSI terminal code escape sequences to hide malicious instructions to the LLM, leveraging the line jumping vulnerability we discovered in MCP.</description></item><item><title>How MCP servers can steal your conversation history</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/04/23/how-mcp-servers-can-steal-your-conversation-history/</link><pubDate>Wed, 23 Apr 2025 10:30:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/04/23/how-mcp-servers-can-steal-your-conversation-history/</guid><description>Malicious MCP servers can inject trigger phrases into tool descriptions to exfiltrate entire conversation histories and steal sensitive credentials and IP.</description></item><item><title>Jumping the line: How MCP servers can attack you before you ever use them</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/04/21/jumping-the-line-how-mcp-servers-can-attack-you-before-you-ever-use-them/</link><pubDate>Mon, 21 Apr 2025 10:30:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/04/21/jumping-the-line-how-mcp-servers-can-attack-you-before-you-ever-use-them/</guid><description>MCP&amp;rsquo;s &amp;rsquo;line jumping&amp;rsquo; vulnerability lets malicious servers inject prompts through tool descriptions to manipulate AI behavior before tools are ever invoked.</description></item></channel></rss>